d-obs.com
Scanné il y a 2 h · Rescanner
Conformité expéditeur
SPF · DKIM · DMARC — 29/50
Durcissement
DNS & transport — 0/50
-
~ SPF 10/15
SPF present with ~all (softfail). Hardfail (-all) is stronger. Uses 6/10 DNS lookups.
v=spf1 a mx ip4:46.105.249.64/28 ip4:137.74.10.192/28 ip4:51.178.241.160/27 include:spf.mailjet.com include:mx.ovh.com ~all
→ Once all senders are listed, tighten ~all to -all.TXT @ v=spf1 a mx ip4:46.105.249.64/28 ip4:137.74.10.192/28 ip4:51.178.241.160/27 include:spf.mailjet.com include:mx.ovh.com -all
-
~ DMARC 7/20
DMARC present — p=none, sp=none.
v=DMARC1; p=none;
→ Strengthen DMARC: raise p to quarantine, then reject, once reports look clean; add rua= to receive aggregate reports.TXT _dmarc.d-obs.com v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@d-obs.com
-
~ DKIM 12/15
DKIM key found (dkim) but looks 1024-bit or weaker: dkim.
dkim
→ Rotate to a 2048-bit DKIM key at your provider. -
✗ CAA 0/10
No CAA records — any certificate authority can issue certs for this domain.
→ Restrict which CAs may issue certificates for your domain (create the security@ mailbox or alias to receive iodef reports).CAA @ 0 issue "letsencrypt.org" 0 iodef "mailto:security@d-obs.com"
-
✗ DANE/TLSA 0/5
No DANE/TLSA records on the MX (mail.d-obs.com).
→ DANE requires DNSSEC. Once the zone is signed, publish a TLSA record at _25._tcp.<mail-server> for each MX host, matching the certificate it serves on port 25. -
✗ MTA-STS 0/10
No MTA-STS record — inbound mail can be downgraded to cleartext.
→ Publish the MTA-STS TXT record AND serve the policy file at https://mta-sts.d-obs.com/.well-known/mta-sts.txt (set id to a fresh YYYYMMDDnn value).TXT _mta-sts.d-obs.com v=STSv1; id=REPLACE_WITH_DATE
-
✗ TLS-RPT 0/5
No TLS-RPT record — you won't be told when mail TLS fails.
→ Publish a TLS-RPT record to receive reports of mail TLS failures.TXT _smtp._tls.d-obs.com v=TLSRPTv1; rua=mailto:tls-reports@d-obs.com
-
✗ BIMI 0/5
No BIMI record found.
→ BIMI requires DMARC at quarantine/reject first. Then publish a BIMI record pointing to an SVG Tiny PS logo (l=) and ideally a VMC certificate (a=). -
✗ DNSSEC 0/10
DNSSEC not detected.
→ Enable DNSSEC at your DNS host, then add the DS record at your registrar to complete the chain of trust. -
✗ TLS web 0/5
HTTPS served with an invalid certificate (self-signed certificate).
→ Fix the certificate: it must be valid, unexpired and issued for this hostname.
Ce domaine n'est qu'un début — surveillez vos 40 domaines et soyez alerté à la moindre dérive.
Rejoindre la liste d'attente