example.com
Scanné à l'instant · Rescanner
Conformité expéditeur
SPF · DKIM · DMARC — 36/50
Durcissement
DNS & transport — 20/30
-
✓ SPF 15/15
SPF present with -all (hardfail) — strongest policy. Uses 0/10 DNS lookups.
v=spf1 -all
-
~ DMARC 18/20
DMARC present — p=reject, sp=reject.
v=DMARC1;p=reject;sp=reject;adkim=s;aspf=s
→ Strengthen DMARC: add rua= to receive aggregate reports.TXT _dmarc.example.com v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@example.com
-
✗ DKIM 3/15
DKIM record present but the key is revoked (empty p=) for: default, google, selector1, selector2, k1, k2, k3, mail, smtp, dkim, s1, s2, mx, email, protonmail, everlytickey1, everlytickey2, cm, mandrill, mxvault.
default, google, selector1, selector2, k1, k2, k3, mail, smtp, dkim, s1, s2, mx, email, protonmail, everlytickey1, everlytickey2, cm, mandrill, mxvault
→ Republish an active public key, or remove the revoked selector record. -
✗ CAA 0/10
No CAA records — any certificate authority can issue certs for this domain.
→ Restrict which CAs may issue certificates for your domain (create the security@ mailbox or alias to receive iodef reports).CAA @ 0 issue "letsencrypt.org" 0 iodef "mailto:security@example.com"
-
– DANE/TLSA 0/5
No mail server (MX) to publish TLSA records under — SMTP DANE does not apply.
-
– MTA-STS 0/10
This domain accepts no mail — there is nothing to downgrade.
-
– TLS-RPT 0/5
This domain accepts no mail — there is no inbound TLS to report on.
-
✗ BIMI 0/5
No BIMI record found.
→ BIMI requires DMARC at quarantine/reject first. Then publish a BIMI record pointing to an SVG Tiny PS logo (l=) and ideally a VMC certificate (a=). -
✓ DNSSEC 10/10
DNSSEC enabled — DS published at the parent, chain of trust complete.
2371 13 2 c988ec423e3880eb8dd8a46fe06ca230ee23f35b578d64e78b29c3e1c83d245a
-
✓ TLS web 10/5
HTTPS active — TLSv1.3.
Ce domaine n'est qu'un début — surveillez vos 40 domaines et soyez alerté à la moindre dérive.
Rejoindre la liste d'attente