d-ons.com
Scanné à l'instant · Rescanner
Conformité expéditeur
SPF · DKIM · DMARC — 0/50
Durcissement
DNS & transport — 0/40
-
✗ SPF 0/15
No SPF record found — anyone can send mail as this domain.
→ Publish an SPF record listing your authorized senders, ending with -all.TXT @ v=spf1 include:_spf.google.com -all
-
✗ DMARC 0/20
No DMARC record found.
→ Publish DMARC. Start at p=none to monitor, then progress to quarantine and reject.TXT _dmarc.d-ons.com v=DMARC1; p=none; rua=mailto:dmarc@d-ons.com
-
✗ DKIM 0/15
No DKIM key found — probed 20 selectors (no known provider in MX/SPF). A custom selector may still exist: selectors are unbounded, so absence cannot be proved from DNS alone.
→ Enable DKIM signing at your email provider and publish the public key it gives you at <selector>._domainkey.d-ons.com. DKIM keys are provider-specific and can't be generated generically. -
✗ CAA 0/10
No CAA records — any certificate authority can issue certs for this domain.
→ Restrict which CAs may issue certificates for your domain (create the security@ mailbox or alias to receive iodef reports).CAA @ 0 issue "letsencrypt.org" 0 iodef "mailto:security@d-ons.com"
-
– DANE/TLSA 0/5
No mail server (MX) to publish TLSA records under — SMTP DANE does not apply.
-
✗ MTA-STS 0/10
No MTA-STS record — inbound mail can be downgraded to cleartext.
→ Publish the MTA-STS TXT record AND serve the policy file at https://mta-sts.d-ons.com/.well-known/mta-sts.txt (set id to a fresh YYYYMMDDnn value).TXT _mta-sts.d-ons.com v=STSv1; id=REPLACE_WITH_DATE
-
✗ TLS-RPT 0/5
No TLS-RPT record — you won't be told when mail TLS fails.
→ Publish a TLS-RPT record to receive reports of mail TLS failures.TXT _smtp._tls.d-ons.com v=TLSRPTv1; rua=mailto:tls-reports@d-ons.com
-
✗ BIMI 0/5
No BIMI record found.
→ BIMI requires DMARC at quarantine/reject first. Then publish a BIMI record pointing to an SVG Tiny PS logo (l=) and ideally a VMC certificate (a=). -
✗ DNSSEC 0/10
DNSSEC not detected.
→ Enable DNSSEC at your DNS host, then add the DS record at your registrar to complete the chain of trust. -
– TLS web 0/5
No public web address — this domain has no website to secure.
Ce domaine n'est qu'un début — surveillez vos 40 domaines et soyez alerté à la moindre dérive.
Rejoindre la liste d'attente