authex
Domain Security Report

facebook.com

B71 / 100
Scan Date
Monday, March 30, 2026
Report ID
280A2687
“Over 90% of cyber attacks begin with email. Authentication is not optional anymore, it is your first line of defense.”
Hemanth Vishnu Akula
Founder & CEO, Authex

Section 01

Executive Summary

Good progress. SPF and DKIM are in place. DKIM needs attention to complete your protection.

Protocol Dashboard

ProtocolStatusScore
DMARCEnforced
32 / 35
SPFConfigured
17 / 25
DKIMKey Revoked
10 / 20
MTA-STSTesting Mode
7 / 10
TLS-RPTConfigured
5 / 5
BIMINot Found
0 / 5

Top Priority Actions

  1. DKIM: The DKIM key is revoked (empty p= tag). Publish a new key for this selector.
  2. BIMI: Publish a BIMI record with your brand SVG logo. Requires DMARC at p=quarantine or p=reject with pct=100.
  3. MTA-STS: Switch MTA-STS policy from testing to enforce once you have verified TLS works for all senders.

Section 02

Compliance Readiness

Assessment of facebook.com against major email security compliance frameworks.

FrameworkReferenceRequirementsStatus
PCI DSS 4.0Req 5.4.1DMARC + SPF + DKIMPartial
Google / Yahoo Bulk Sender2024 RequirementsDMARC + SPF + DKIMPartial
NIST SP 800-177Rev. 1SPF + DKIM + DMARCPartial
CISA BOD 18-01Binding Operational DirectiveDMARC (p=reject)Compliant
Cyber EssentialsUK NCSCDMARC + SPFCompliant

Section 03

DMARC. Domain-based Message Authentication, Reporting & Conformance

EnforcedRFC 7489
32 / 35

DMARC policy is set to reject, providing maximum protection against spoofing.

Configuration Details

Policyreject
Percentage100%
Aggregate Reportingmailto:a@dmarc.facebookmail.com
Forensic Reportingmailto:fb-dmarc@datafeeds.phishlabs.com
DKIM Alignmentrelaxed
SPF Alignmentrelaxed

DNS Record

v=DMARC1; p=reject; rua=mailto:a@dmarc.facebookmail.com; ruf=mailto:fb-dmarc@datafeeds.phishlabs.com; pct=100

Section 04

SPF. Sender Policy Framework

ConfiguredRFC 7208
17 / 25

SPF record found with 1 DNS lookup and no all mechanism.

Configuration Details

All Mechanismnot specified
DNS Lookups1/10
Record Length33 bytes

DNS Record

v=spf1 redirect=_spf.facebook.com

Section 05

DKIM. DomainKeys Identified Mail

Key RevokedRFC 6376
10 / 20

DKIM key at selector "default" is revoked. Messages cannot be verified with this key.

Configuration Details

Selectordefault
Algorithmrsa-sha256
StatusREVOKED (empty p= tag)

DNS Record

default._domainkey: t=y; k=rsa; p=;
Recommendation: The DKIM key is revoked (empty p= tag). Publish a new key for this selector.

Section 06

Transport Security

Transport-layer email security protocols that protect messages in transit between mail servers.

MTA-STS Mail Transfer Agent Strict Transport Security

Testing ModeRFC 8461
7 / 10

MTA-STS DNS record exists for facebook.com. Policy mode: testing.

Policy ID20191202T113700
Policy Fileaccessible
Modetesting
Max Age86400s (below recommended 7d)
MX Matchpolicy MX matches actual MX
v=STSv1; id=20191202T113700;
Recommendation: Switch MTA-STS policy from testing to enforce once you have verified TLS works for all senders.

TLS-RPT TLS Reporting

ConfiguredRFC 8460
5 / 5

TLS-RPT is configured for facebook.com. Reports on TLS delivery failures will be sent to mailto:sts-reports@facebookmail.com.

Report URImailto:sts-reports@facebookmail.com
v=TLSRPTv1;rua=mailto:sts-reports@facebookmail.com

BIMI Brand Indicators for Message Identification

Not FoundRFC 9495
0 / 5

No BIMI record found for facebook.com. Brand logo will not appear in supporting email clients.

Recommendation: Publish a BIMI record with your brand SVG logo. Requires DMARC at p=quarantine or p=reject with pct=100.

Section 07

Remediation Plan

Prioritized findings and recommended fixes. These can be implemented by your internal IT team, or you can use Authex to monitor, manage, and automate these changes with our AI-powered platform starting at $9/domain per month.

#ProtocolFindingSeverityFix
1DKIMKey RevokedHighThe DKIM key is revoked (empty p= tag). Publish a new key for this selector.
2BIMINot FoundHighPublish a BIMI record with your brand SVG logo. Requires DMARC at p=quarantine or p=reject with pct=100.
3MTA-STSTesting ModeMediumSwitch MTA-STS policy from testing to enforce once you have verified TLS works for all senders.
Need help fixing these?

Authex continuously monitors your email authentication, detects misconfigurations, and helps you fix them. Our AI agent handles SPF flattening, DKIM rotation, and DMARC enforcement automatically. DIY plans start at $9/domain. Managed plans include a dedicated security engineer. Visit authex.online to get started with a free scan.


Section 08

Scoring Methodology

Protocol Weights

ProtocolMax PointsWeight
DMARC3535%
SPF2525%
DKIM2020%
MTA-STS1010%
TLS-RPT55%
BIMI55%

Grade Scale

GradeScore Range
A+95 - 100
A85 - 94
B70 - 84
C50 - 69
D30 - 49
F0 - 29
authex
Generated by Authex. authex.online
Mon, 30 Mar 2026 22:53:49 GMT