Last scanned 2h ago · Mar 30, 2026, 10:53 PM
No email authentication detected. Your domain is open to spoofing. anyone can send emails as you.
First scan · Mar 30, 2026, 10:53 PM
Publish a DMARC record starting with p=none and add rua reporting to begin monitoring authentication.
Publish an SPF record listing your authorized email senders (e.g. v=spf1 include:_spf.google.com ~all).
Ensure your email provider has published DKIM keys. If using a custom selector, DKIM may still be active.
Publish an MTA-STS TXT record and host a policy file at https://mta-sts.yourdomain/.well-known/mta-sts.txt.
Publish a TLS-RPT record to receive reports when sending servers fail to establish encrypted connections.
Publish a BIMI record with your brand SVG logo. Requires DMARC at p=quarantine or p=reject with pct=100.