data-observer.com
Scanné à l'instant · Rescanner
Conformité expéditeur
SPF · DKIM · DMARC — 29/50
Durcissement
DNS & transport — 17/50
-
~ SPF 10/15
SPF present with ~all (softfail). Hardfail (-all) is stronger. Uses 6/10 DNS lookups.
v=spf1 a mx ip4:46.105.249.64/28 ip4:137.74.10.192/28 ip4:51.178.241.160/27 include:spf.mailjet.com include:mx.ovh.com ~all
→ Once all senders are listed, tighten ~all to -all.TXT @ v=spf1 a mx ip4:46.105.249.64/28 ip4:137.74.10.192/28 ip4:51.178.241.160/27 include:spf.mailjet.com include:mx.ovh.com -all
-
~ DMARC 7/20
DMARC present — p=none, sp=none.
v=DMARC1; p=none;
→ Strengthen DMARC: raise p to quarantine, then reject, once reports look clean; add rua= to receive aggregate reports.TXT _dmarc.data-observer.com v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@data-observer.com
-
~ DKIM 12/15
DKIM key found (mail, dkim) but looks 1024-bit or weaker: mail, dkim.
mail, dkim
→ Rotate to a 2048-bit DKIM key at your provider. -
✗ CAA 0/10
No CAA records — any certificate authority can issue certs for this domain.
→ Restrict which CAs may issue certificates for your domain (create the security@ mailbox or alias to receive iodef reports).CAA @ 0 issue "letsencrypt.org" 0 iodef "mailto:security@data-observer.com"
-
✗ DANE/TLSA 0/5
No DANE/TLSA records on the MX (kolab.data-observer.com).
→ DANE requires DNSSEC. Once the zone is signed, publish a TLSA record at _25._tcp.<mail-server> for each MX host, matching the certificate it serves on port 25. -
✗ MTA-STS 0/10
No MTA-STS record — inbound mail can be downgraded to cleartext.
→ Publish the MTA-STS TXT record AND serve the policy file at https://mta-sts.data-observer.com/.well-known/mta-sts.txt (set id to a fresh YYYYMMDDnn value).TXT _mta-sts.data-observer.com v=STSv1; id=REPLACE_WITH_DATE
-
✗ TLS-RPT 0/5
No TLS-RPT record — you won't be told when mail TLS fails.
→ Publish a TLS-RPT record to receive reports of mail TLS failures.TXT _smtp._tls.data-observer.com v=TLSRPTv1; rua=mailto:tls-reports@data-observer.com
-
✗ BIMI 0/5
No BIMI record found.
→ BIMI requires DMARC at quarantine/reject first. Then publish a BIMI record pointing to an SVG Tiny PS logo (l=) and ideally a VMC certificate (a=). -
✓ DNSSEC 10/10
DNSSEC enabled — DS published at the parent, chain of trust complete.
58085 8 2 785c3c2d98fdcc50c9655c2622f4eb7a88201371465829ba4ca13deeed7508aa
-
~ TLS web 7/5
HTTPS active — TLSv1.2. TLS 1.3 is recommended.
→ Enable TLS 1.3 on your web server.
Ce domaine n'est qu'un début — surveillez vos 40 domaines et soyez alerté à la moindre dérive.
Rejoindre la liste d'attente