authex
Domain Security Report

authex.online

C74 / 100
Scan Date
Monday, March 30, 2026
Report ID
78031145
“Over 90% of cyber attacks begin with email. Authentication is not optional anymore, it is your first line of defense.”
Hemanth Vishnu Akula
Founder & CEO, Authex

Section 01

Executive Summary

authex.online has a good email security foundation with a grade of C. 4 protocols fully configured. Needs attention: DMARC, BIMI. Addressing remaining gaps would significantly strengthen protection against spoofing.

Protocol Dashboard

ProtocolStatusScore
DMARCMonitor Only (p=none)
23 / 35
SPFHard Fail (-all)
23 / 25
DKIMFound (selector: selector1)
20 / 20
MTA-STSDNS Record Only
2 / 10
TLS-RPTConfigured
5 / 5
BIMIIncomplete
1 / 5

Top Priority Actions

  1. DMARC: Progress to p=quarantine and then p=reject once you have identified all legitimate senders via RUA reports.
  2. BIMI: Add an SVG Tiny PS logo URL to your BIMI record (l= tag).
  3. MTA-STS: Host a valid MTA-STS policy file at https://mta-sts.yourdomain/.well-known/mta-sts.txt.

Section 02

Compliance Readiness

Assessment of authex.online against major email security compliance frameworks.

FrameworkReferenceRequirementsStatus
PCI DSS 4.0Req 5.4.1DMARC + SPF + DKIMPartial
Google / Yahoo Bulk Sender2024 RequirementsDMARC + SPF + DKIMPartial
NIST SP 800-177Rev. 1SPF + DKIM + DMARCPartial
CISA BOD 18-01Binding Operational DirectiveDMARC (p=reject)Non-Compliant
Cyber EssentialsUK NCSCDMARC + SPFPartial

Section 03

DMARC. Domain-based Message Authentication, Reporting & Conformance

Monitor Only (p=none)RFC 7489
23 / 35

DMARC policy is set to none (monitor only). Unauthorized emails are still delivered.

Configuration Details

Policynone
Aggregate Reportingmailto:reports@authex.online
Forensic Reportingmailto:reports@authex.online
DKIM Alignmentrelaxed
SPF Alignmentrelaxed

DNS Record

v=DMARC1; p=none; rua=mailto:reports@authex.online; ruf=mailto:reports@authex.online
Recommendation: Progress to p=quarantine and then p=reject once you have identified all legitimate senders via RUA reports.

Section 04

SPF. Sender Policy Framework

Hard Fail (-all)RFC 7208
23 / 25

SPF record found with 2 DNS lookups and -all.

Configuration Details

All Mechanism-all (hard fail)
DNS Lookups2/10
Record Length58 bytes

DNS Record

v=spf1 include:authex-online.spf.nullify-security.com -all

Section 05

DKIM. DomainKeys Identified Mail

Found (selector: selector1)RFC 6376
20 / 20

DKIM key found at selector "selector1". Email integrity and sender authenticity can be verified.

Configuration Details

Selectorselector1
Key Length2048+ bit
Algorithmrsa-sha256

DNS Record

v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApcWS5JJHmpUD93IRuWr5Dj6o6azdr27Rj1wrvdw1xUMmjukFesO652laNebWuwLL3C0Xt2KBh91fvYMWP9Q4jHNI6CvBa6RoRfv8ep1704hr/X+k/UwII84TgLtJGQKHJd0kiPWRXp/XyAr5Nz85AxAku5UxxMVvX2DguJU9+UZkk8A74Ins9X0B2CHrY6d7XM6f31uXtXVQlEos5qFB5YlvYzZiuh27VHBu6ghK6nFX6n...

Section 06

Transport Security

Transport-layer email security protocols that protect messages in transit between mail servers.

MTA-STS Mail Transfer Agent Strict Transport Security

DNS Record OnlyRFC 8461
2 / 10

MTA-STS DNS record exists for authex.online. Policy file could not be verified.

Policy IDd5f0c5367773
Policy FileHTTP 404
v=STSv1; id=d5f0c5367773
Recommendation: Host a valid MTA-STS policy file at https://mta-sts.yourdomain/.well-known/mta-sts.txt.

TLS-RPT TLS Reporting

ConfiguredRFC 8460
5 / 5

TLS-RPT is configured for authex.online. Reports on TLS delivery failures will be sent to mailto:reports@authex.online.

Report URImailto:reports@authex.online
v=TLSRPTv1; rua=mailto:reports@authex.online

Section 07

BIMI. Brand Indicators for Message Identification

IncompleteRFC 9495
1 / 5

BIMI record exists for authex.online but is missing key components.

DMARC Prerequisitenot met (requires p=quarantine/reject with pct=100)
v=BIMI1
Recommendation: Add an SVG Tiny PS logo URL to your BIMI record (l= tag).

Section 08

Remediation Plan

Prioritized findings and recommended fixes. These can be implemented by your internal IT team, or you can use Authex to monitor, manage, and automate these changes with our AI-powered platform starting at $9/domain per month.

#ProtocolFindingSeverityFix
1DMARCMonitor Only (p=none)MediumProgress to p=quarantine and then p=reject once you have identified all legitimate senders via RUA reports.
2BIMIIncompleteMediumAdd an SVG Tiny PS logo URL to your BIMI record (l= tag).
3MTA-STSDNS Record OnlyLowHost a valid MTA-STS policy file at https://mta-sts.yourdomain/.well-known/mta-sts.txt.
Need help fixing these?

Authex continuously monitors your email authentication, detects misconfigurations, and helps you fix them. Our AI agent handles SPF flattening, DKIM rotation, and DMARC enforcement automatically. DIY plans start at $9/domain. Managed plans include a dedicated security engineer. Visit authex.online to get started with a free scan.


Section 09

Scoring Methodology

Protocol Weights

ProtocolMax PointsWeight
DMARC3535%
SPF2525%
DKIM2020%
MTA-STS1010%
TLS-RPT55%
BIMI55%

Grade Scale

GradeScore Range
A+95 - 100
A85 - 94
B70 - 84
C50 - 69
D30 - 49
F0 - 29
authex
Generated by Authex. authex.online
Mon, 30 Mar 2026 19:40:10 GMT