laposte.fr
Scanné il y a 2 h · Rescanner
Conformité expéditeur
SPF · DKIM · DMARC — 36/50
Durcissement
DNS & transport — 10/50
-
✓ SPF 15/15
SPF present with -all (hardfail) — strongest policy. Uses 6/10 DNS lookups.
v=spf1 include:_spfstd_sccc.laposte.fr include:_spfmm_sccc.laposte.fr include:_spfal_sccc.laposte.fr include:_spftmp_sccc.laposte.fr include:mail.zendesk.com mx -all
-
~ DMARC 9/20
DMARC present — p=none, sp=none.
v=DMARC1; p=none; pct=100; rua=mailto:laposte.rua@emailsecurity.merox.io
→ Strengthen DMARC: raise p to quarantine, then reject, once reports look clean.TXT _dmarc.laposte.fr v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@laposte.fr
-
~ DKIM 12/15
DKIM key found (selector2) but looks 1024-bit or weaker: selector2.
selector2
→ Rotate to a 2048-bit DKIM key at your provider. -
✗ CAA 0/10
No CAA records — any certificate authority can issue certs for this domain.
→ Restrict which CAs may issue certificates for your domain (create the security@ mailbox or alias to receive iodef reports).CAA @ 0 issue "letsencrypt.org" 0 iodef "mailto:security@laposte.fr"
-
✗ DANE/TLSA 0/5
No DANE/TLSA records on the MX (rpi0i753.laposte.fr, rpi0i751.laposte.fr, rpi0i693.laposte.fr, rpi0i691.laposte.fr).
→ DANE requires DNSSEC. Once the zone is signed, publish a TLSA record at _25._tcp.<mail-server> for each MX host, matching the certificate it serves on port 25. -
✗ MTA-STS 0/10
No MTA-STS record — inbound mail can be downgraded to cleartext.
→ Publish the MTA-STS TXT record AND serve the policy file at https://mta-sts.laposte.fr/.well-known/mta-sts.txt (set id to a fresh YYYYMMDDnn value).TXT _mta-sts.laposte.fr v=STSv1; id=REPLACE_WITH_DATE
-
✗ TLS-RPT 0/5
No TLS-RPT record — you won't be told when mail TLS fails.
→ Publish a TLS-RPT record to receive reports of mail TLS failures.TXT _smtp._tls.laposte.fr v=TLSRPTv1; rua=mailto:tls-reports@laposte.fr
-
✗ BIMI 0/5
No BIMI record found.
→ BIMI requires DMARC at quarantine/reject first. Then publish a BIMI record pointing to an SVG Tiny PS logo (l=) and ideally a VMC certificate (a=). -
✗ DNSSEC 0/10
DNSSEC not detected.
→ Enable DNSSEC at your DNS host, then add the DS record at your registrar to complete the chain of trust. -
✓ TLS web 10/5
HTTPS active — TLSv1.3.
Ce domaine n'est qu'un début — surveillez vos 40 domaines et soyez alerté à la moindre dérive.
Rejoindre la liste d'attente