github.com
Scanné à l'instant · Rescanner
Conformité expéditeur
SPF · DKIM · DMARC — 39/50
Durcissement
DNS & transport — 17/45
-
~ SPF 10/15
SPF present with ~all (softfail). Hardfail (-all) is stronger. Uses 10/10 DNS lookups. One more include would break it.
v=spf1 ip4:192.30.252.0/22 include:spf.protection.outlook.com include:_netblocks.google.com include:_netblocks2.google.com include:mail.zendesk.com include:_spf.salesforce.com include:servers.mcsv.net include:mktomail.com include:sendgrid.net ip4:62.253.227.114 ip4:166.78.69.169 ip4:166.78.69.170 ip4:166.78.71.131 ~all
→ Once all senders are listed, tighten ~all to -all.TXT @ v=spf1 ip4:192.30.252.0/22 include:spf.protection.outlook.com include:_netblocks.google.com include:_netblocks2.google.com include:mail.zendesk.com include:_spf.salesforce.com include:servers.mcsv.net include:mktomail.com include:sendgrid.net ip4:62.253.227.114 ip4:166.78.69.169 ip4:166.78.69.170 ip4:166.78.71.131 -all
-
~ DMARC 17/20
DMARC present — p=quarantine, sp=reject.
v=DMARC1; p=quarantine; sp=reject; pct=100; rua=mailto:dmarc@github.com; ruf=mailto:dmarc@github.com; fo=1
→ Strengthen DMARC: raise p to quarantine, then reject, once reports look clean.TXT _dmarc.github.com v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@github.com
-
~ DKIM 12/15
DKIM key found (google, selector1, k1, k2, s1, s2) but looks 1024-bit or weaker: selector1, k1.
google, selector1, k1, k2, s1, s2
→ Rotate to a 2048-bit DKIM key at your provider. -
~ CAA 7/10
CAA present but no iodef reporting.
0 issue "sectigo.com" | 0 issuewild "digicert.com" | 0 issuewild "letsencrypt.org" | 0 issuewild "sectigo.com" | 0 issue "digicert.com" | 0 issue "globalsign.com" | 0 issue "letsencrypt.org"
→ Add an iodef record to be notified of unauthorized issuance attempts.CAA @ 0 iodef "mailto:security@github.com"
-
– DANE/TLSA 0/5
Mail is hosted by a third party (github-com.mail.protection.outlook.com) that publishes no TLSA — DANE lives in the mail server's zone, out of this domain owner's hands.
-
✗ MTA-STS 0/10
No MTA-STS record — inbound mail can be downgraded to cleartext.
→ Publish the MTA-STS TXT record AND serve the policy file at https://mta-sts.github.com/.well-known/mta-sts.txt (set id to a fresh YYYYMMDDnn value).TXT _mta-sts.github.com v=STSv1; id=REPLACE_WITH_DATE
-
✗ TLS-RPT 0/5
No TLS-RPT record — you won't be told when mail TLS fails.
→ Publish a TLS-RPT record to receive reports of mail TLS failures.TXT _smtp._tls.github.com v=TLSRPTv1; rua=mailto:tls-reports@github.com
-
✗ BIMI 0/5
No BIMI record found.
→ BIMI requires DMARC at quarantine/reject first. Then publish a BIMI record pointing to an SVG Tiny PS logo (l=) and ideally a VMC certificate (a=). -
✗ DNSSEC 0/10
DNSSEC not detected.
→ Enable DNSSEC at your DNS host, then add the DS record at your registrar to complete the chain of trust. -
✓ TLS web 10/5
HTTPS active — TLSv1.3.
Ce domaine n'est qu'un début — surveillez vos 40 domaines et soyez alerté à la moindre dérive.
Rejoindre la liste d'attente