lavicon.dev
Scanné il y a 89 min · Rescanner
Conformité expéditeur
SPF · DKIM · DMARC — 29/50
Durcissement
DNS & transport — 10/45
-
✗ SPF 3/15
Multiple SPF records (2) — there must be exactly one.
v=spf1 include:_mailcust.gandi.net ?all | v=spf1 include:_spf.gandi.net ~all
→ Merge into a single SPF TXT record; multiple SPF records make SPF invalid. -
~ DMARC 16/20
DMARC present — p=quarantine, sp=quarantine.
v=DMARC1; p=quarantine; rua=mailto:contact@lavicon.dev; ruf=mailto:contact@lavicon.dev; sp=quarantine; adkim=r; aspf=r;
→ Strengthen DMARC: raise p to quarantine, then reject, once reports look clean.TXT _dmarc.lavicon.dev v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@lavicon.dev
-
~ DKIM 10/15
DKIM key found (mail) but in testing mode (t=y) — receivers ignore the signature.
mail
→ Remove the t=y tag once signing is verified. -
✗ CAA 0/10
No CAA records — any certificate authority can issue certs for this domain.
→ Restrict which CAs may issue certificates for your domain (create the security@ mailbox or alias to receive iodef reports).CAA @ 0 issue "letsencrypt.org" 0 iodef "mailto:security@lavicon.dev"
-
– DANE/TLSA 0/5
Mail is hosted by a third party (fb.mail.gandi.net, spool.mail.gandi.net) that publishes no TLSA — DANE lives in the mail server's zone, out of this domain owner's hands.
-
✗ MTA-STS 0/10
No MTA-STS record — inbound mail can be downgraded to cleartext.
→ Publish the MTA-STS TXT record AND serve the policy file at https://mta-sts.lavicon.dev/.well-known/mta-sts.txt (set id to a fresh YYYYMMDDnn value).TXT _mta-sts.lavicon.dev v=STSv1; id=REPLACE_WITH_DATE
-
✗ TLS-RPT 0/5
No TLS-RPT record — you won't be told when mail TLS fails.
→ Publish a TLS-RPT record to receive reports of mail TLS failures.TXT _smtp._tls.lavicon.dev v=TLSRPTv1; rua=mailto:tls-reports@lavicon.dev
-
✗ BIMI 0/5
No BIMI record found.
→ BIMI requires DMARC at quarantine/reject first. Then publish a BIMI record pointing to an SVG Tiny PS logo (l=) and ideally a VMC certificate (a=). -
✗ DNSSEC 0/10
DNSSEC not detected.
→ Enable DNSSEC at your DNS host, then add the DS record at your registrar to complete the chain of trust. -
✓ TLS web 10/5
HTTPS active — TLSv1.3.
Ce domaine n'est qu'un début — surveillez vos 40 domaines et soyez alerté à la moindre dérive.
Rejoindre la liste d'attente