authex
Domain Security Report

office.com

D36 / 100
Scan Date
Monday, March 30, 2026
Report ID
12B0E2D2
“Over 90% of cyber attacks begin with email. Authentication is not optional anymore, it is your first line of defense.”
Hemanth Vishnu Akula
Founder & CEO, Authex

Section 01

Executive Summary

Only DMARC is configured. Your domain needs SPF, DKIM, and DMARC working together to prevent spoofing.

Protocol Dashboard

ProtocolStatusScore
DMARCQuarantine
29 / 35
SPFNot Found
0 / 25
DKIMNot Detected
0 / 20
MTA-STSTesting Mode
7 / 10
TLS-RPTNot Configured
0 / 5
BIMINot Found
0 / 5

Top Priority Actions

  1. SPF: Publish an SPF record listing your authorized email senders (e.g. v=spf1 include:_spf.google.com ~all).
  2. DKIM: Ensure your email provider has published DKIM keys. If using a custom selector, DKIM may still be active.
  3. TLS-RPT: Publish a TLS-RPT record to receive reports when sending servers fail to establish encrypted connections.

Section 02

Compliance Readiness

Assessment of office.com against major email security compliance frameworks.

FrameworkReferenceRequirementsStatus
PCI DSS 4.0Req 5.4.1DMARC + SPF + DKIMPartial
Google / Yahoo Bulk Sender2024 RequirementsDMARC + SPF + DKIMPartial
NIST SP 800-177Rev. 1SPF + DKIM + DMARCPartial
CISA BOD 18-01Binding Operational DirectiveDMARC (p=reject)Non-Compliant
Cyber EssentialsUK NCSCDMARC + SPFPartial

Section 03

DMARC. Domain-based Message Authentication, Reporting & Conformance

QuarantineRFC 7489
29 / 35

DMARC policy is set to quarantine. Suspicious emails are filtered but not blocked outright.

Configuration Details

Policyquarantine
Percentage100%
Aggregate Reportingmailto:rua@dmarc.microsoft
Forensic Reportingmailto:ruf@dmarc.microsoft
DKIM Alignmentrelaxed
SPF Alignmentrelaxed

DNS Record

v=DMARC1; p=quarantine; pct=100; rua=mailto:rua@dmarc.microsoft; ruf=mailto:ruf@dmarc.microsoft; fo=1
Recommendation: Consider escalating to p=reject once compliance is consistently above 98%.

Section 04

SPF. Sender Policy Framework

Not FoundRFC 7208
0 / 25

No SPF record found for office.com. Receiving servers cannot verify authorized senders.

Recommendation: Publish an SPF record listing your authorized email senders (e.g. v=spf1 include:_spf.google.com ~all).

Section 05

DKIM. DomainKeys Identified Mail

Not DetectedRFC 6376
0 / 20

No DKIM record found for common selectors on office.com. DKIM may use a custom selector that could not be auto-detected.

Recommendation: Ensure your email provider has published DKIM keys. If using a custom selector, DKIM may still be active.

Section 06

Transport Security

Transport-layer email security protocols that protect messages in transit between mail servers.

MTA-STS Mail Transfer Agent Strict Transport Security

Testing ModeRFC 8461
7 / 10

MTA-STS DNS record exists for office.com. Policy mode: testing.

Policy ID20180321T030303
Policy Fileaccessible
Modetesting
Max Age604800s (7d)
MX Matchpolicy MX does not match actual MX
v=STSv1; id=20180321T030303;
Recommendation: Switch MTA-STS policy from testing to enforce once you have verified TLS works for all senders.

TLS-RPT TLS Reporting

Not ConfiguredRFC 8460
0 / 5

No TLS-RPT record found for office.com. TLS delivery failures are invisible.

Recommendation: Publish a TLS-RPT record to receive reports when sending servers fail to establish encrypted connections.

BIMI Brand Indicators for Message Identification

Not FoundRFC 9495
0 / 5

No BIMI record found for office.com. Brand logo will not appear in supporting email clients.

Recommendation: Publish a BIMI record with your brand SVG logo. Requires DMARC at p=quarantine or p=reject with pct=100.

Section 07

Remediation Plan

Prioritized findings and recommended fixes. These can be implemented by your internal IT team, or you can use Authex to monitor, manage, and automate these changes with our AI-powered platform starting at $9/domain per month.

#ProtocolFindingSeverityFix
1SPFNot FoundHighPublish an SPF record listing your authorized email senders (e.g. v=spf1 include:_spf.google.com ~all).
2DKIMNot DetectedHighEnsure your email provider has published DKIM keys. If using a custom selector, DKIM may still be active.
3TLS-RPTNot ConfiguredHighPublish a TLS-RPT record to receive reports when sending servers fail to establish encrypted connections.
4BIMINot FoundHighPublish a BIMI record with your brand SVG logo. Requires DMARC at p=quarantine or p=reject with pct=100.
5MTA-STSTesting ModeMediumSwitch MTA-STS policy from testing to enforce once you have verified TLS works for all senders.
6DMARCQuarantineLowConsider escalating to p=reject once compliance is consistently above 98%.
Need help fixing these?

Authex continuously monitors your email authentication, detects misconfigurations, and helps you fix them. Our AI agent handles SPF flattening, DKIM rotation, and DMARC enforcement automatically. DIY plans start at $9/domain. Managed plans include a dedicated security engineer. Visit authex.online to get started with a free scan.


Section 08

Scoring Methodology

Protocol Weights

ProtocolMax PointsWeight
DMARC3535%
SPF2525%
DKIM2020%
MTA-STS1010%
TLS-RPT55%
BIMI55%

Grade Scale

GradeScore Range
A+95 - 100
A85 - 94
B70 - 84
C50 - 69
D30 - 49
F0 - 29
authex
Generated by Authex. authex.online
Mon, 30 Mar 2026 22:53:53 GMT