med-observer.com
Scanné il y a 77 min · Rescanner
Conformité expéditeur
SPF · DKIM · DMARC — 7/50
Durcissement
DNS & transport — 10/50
-
~ SPF 7/15
SPF present with ?all (neutral) — provides little protection. Uses 1/10 DNS lookups.
v=spf1 ip4:85.31.210.0/24 ip4:85.31.222.0/24 ip4:46.105.249.64/28 mx ?all
→ Change ?all to -all (hardfail).TXT @ v=spf1 ip4:85.31.210.0/24 ip4:85.31.222.0/24 ip4:46.105.249.64/28 mx -all
-
✗ DMARC 0/20
No DMARC record found.
→ Publish DMARC. Start at p=none to monitor, then progress to quarantine and reject.TXT _dmarc.med-observer.com v=DMARC1; p=none; rua=mailto:dmarc@med-observer.com
-
✗ DKIM 0/15
No DKIM key found — probed 20 selectors (no known provider in MX/SPF). A custom selector may still exist: selectors are unbounded, so absence cannot be proved from DNS alone.
→ Enable DKIM signing at your email provider and publish the public key it gives you at <selector>._domainkey.med-observer.com. DKIM keys are provider-specific and can't be generated generically. -
✗ CAA 0/10
No CAA records — any certificate authority can issue certs for this domain.
→ Restrict which CAs may issue certificates for your domain (create the security@ mailbox or alias to receive iodef reports).CAA @ 0 issue "letsencrypt.org" 0 iodef "mailto:security@med-observer.com"
-
✗ DANE/TLSA 0/5
No DANE/TLSA records on the MX (mail.med-observer.com).
→ DANE requires DNSSEC. Once the zone is signed, publish a TLSA record at _25._tcp.<mail-server> for each MX host, matching the certificate it serves on port 25. -
✗ MTA-STS 0/10
No MTA-STS record — inbound mail can be downgraded to cleartext.
→ Publish the MTA-STS TXT record AND serve the policy file at https://mta-sts.med-observer.com/.well-known/mta-sts.txt (set id to a fresh YYYYMMDDnn value).TXT _mta-sts.med-observer.com v=STSv1; id=REPLACE_WITH_DATE
-
✗ TLS-RPT 0/5
No TLS-RPT record — you won't be told when mail TLS fails.
→ Publish a TLS-RPT record to receive reports of mail TLS failures.TXT _smtp._tls.med-observer.com v=TLSRPTv1; rua=mailto:tls-reports@med-observer.com
-
✗ BIMI 0/5
No BIMI record found.
→ BIMI requires DMARC at quarantine/reject first. Then publish a BIMI record pointing to an SVG Tiny PS logo (l=) and ideally a VMC certificate (a=). -
✗ DNSSEC 0/10
DNSSEC not detected.
→ Enable DNSSEC at your DNS host, then add the DS record at your registrar to complete the chain of trust. -
✓ TLS web 10/5
HTTPS active — TLSv1.3.
Ce domaine n'est qu'un début — surveillez vos 40 domaines et soyez alerté à la moindre dérive.
Rejoindre la liste d'attente