oc-wh.org

Last scanned 4h ago · Mar 30, 2026, 09:22 PM

B71/100

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

DMARC Policy: quarantine30 scans total

Protocol Status

DMARC
30/35
Quarantine
SPF
21/25
Soft Fail (~all)
DKIM
20/20
3 keys found
MTA-STS
0/10
Not Configured
TLS-RPT
0/5
Not Configured
BIMI
0/5
Not Found

Score History

B71/100
Mar 30, 2026, 09:22 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 09:19 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 09:08 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 09:01 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 08:35 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 08:32 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 08:29 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 08:29 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 08:27 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 08:27 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 08:26 PM

Your domain is protected. SPF, DKIM, and DMARC are configured. Suspicious emails go to spam. consider moving to full reject when ready.

View report →
B71/100
Mar 30, 2026, 08:21 PM

Suspicious emails are sent to spam, but not fully blocked yet. Your emails should reach inboxes reliably. Emails in transit can be intercepted — no transport encryption enforced.

View report →
B71/100
Mar 30, 2026, 08:18 PM

Good foundation — MTA-STS, TLS-RPT, BIMI not configured.

View report →
B71/100
Mar 30, 2026, 08:16 PM

oc-wh.org has a good email security foundation with a grade of B. 3 protocols fully configured. Missing: MTA-STS, TLS-RPT, BIMI. Addressing remaining gaps would significantly strengthen protection against spoofing.

View report →
B71/100
Mar 30, 2026, 08:15 PM

oc-wh.org has a good email security foundation with a grade of B. 3 protocols fully configured. Missing: MTA-STS, TLS-RPT, BIMI. Addressing remaining gaps would significantly strengthen protection against spoofing.

View report →
B71/100
Mar 30, 2026, 08:12 PM

oc-wh.org has a good email security foundation with a grade of B. 3 protocols fully configured. Missing: MTA-STS, TLS-RPT, BIMI. Addressing remaining gaps would significantly strengthen protection against spoofing.

View report →
C68/100
Mar 30, 2026, 08:05 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 08:05 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 08:00 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 08:00 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 07:50 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 07:46 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 07:46 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 07:45 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 07:45 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 07:43 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 07:43 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C68/100
Mar 30, 2026, 07:41 PM

oc-wh.org has partial email authentication (grade C). Only 3 of 6 protocols are properly configured. MTA-STS, TLS-RPT, BIMI are not configured, leaving the domain vulnerable to spoofing and phishing. Immediate action is recommended.

View report →
C+65/100
Mar 30, 2026, 07:24 PM
F35/100
Mar 30, 2026, 04:11 PM

Latest Scan Details

DMARCQuarantine
30/35RFC RFC 7489

Detected Record

v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:reports@authex.online; ruf=mailto:reports@authex.online

Policy

quarantine

Aggregate Reporting

mailto:reports@authex.online

Forensic Reporting

mailto:reports@authex.online

Subdomain Policy

quarantine

DKIM Alignment

relaxed

SPF Alignment

relaxed

Consider escalating to p=reject once compliance is consistently above 98%.

SPFSoft Fail (~all)
21/25RFC RFC 7208

Detected Record

v=spf1 include:spf.protection.outlook.com ~all

All Mechanism

~all (soft fail)

DNS Lookups

2/10

Record Length

46 bytes

Consider tightening to -all for stricter enforcement alongside your DMARC policy.

DKIM3 keys found
20/20RFC RFC 6376

Detected Record

selector1._domainkey:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD12byf2ct4ksWGzqtffjunnL6o9pRXpx0DAjNWBEUsbzYrdUHD3ZLKQ9mNjrutRNgQ0xOjLzBU8SSXJvGwgRQ3AYExMr5Kqgslfh8Wg6cRGGwQrsofUFp27GtRin4f3SJrNMTCySNuMMXUw0...

s1._domainkey:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvq97kwEweQdjh848wud2CCvWFfDdPwrc0E09NdkLzcD8dQt/+4TJ2FoZQO5P71HoSkoHekTUgq63ybguB+f4w2OdgvBScwoOAtM1BuXoy0d9VxcQlmbqts6aoIx/TdMKEUYxMcEmw9SatP...

s2._domainkey:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+AUaPGxDsIZRVY4JUun95298WS4HiPpXd7z7tTimBbw5O8wCP5MIgbfBo3m2hKfMITt61pl3h5O7MJ1aZls8PfcocOI2E1IfMphojtsaUvBDirjx3Q8SkSgMVY6w9Jei1vXIvuaJCYPYH4A8dao...

Selectors

selector1, s1, s2

Key Length

2048+ bit

Algorithm

rsa-sha256

MTA-STSNot Configured
0/10RFC RFC 8461

Publish an MTA-STS TXT record and host a policy file at https://mta-sts.yourdomain/.well-known/mta-sts.txt.

TLS-RPTNot Configured
0/5RFC RFC 8460

Publish a TLS-RPT record to receive reports when sending servers fail to establish encrypted connections.

BIMINot Found
0/5RFC RFC 9495

Publish a BIMI record with your brand SVG logo. Requires DMARC at p=quarantine or p=reject with pct=100.