← Interactive report

facebook.com

warnScanned ·
Summary

facebook.com has warnings

0To fix now
2Recommended
4Healthy

DNS & email auth

warnLast checked
Findings4 findings

Recommended (1)

  • DKIM selector default publishes an empty revoked key.

    DKIM

    default (default._domainkey.facebook.com)

    How to fix

    Remove the record if the key is retired, or re-publish the public key if the selector is still in use.

Healthy (3)

  • 1 MX record found.

    MX
  • SPF record is valid, using 1 of 10 DNS lookups.

    SPF
  • DMARC policy is enforced with p=reject.

    DMARC

Evidence

MX

1 record
  • smtpin.vvv.facebook.compriority 10

SPF

1 of 10 lookups
DNS lookups1 / 10
facebook.com
redirect:_spf.facebook.com

Root TXT

6 records
  • google-site-verification=sK6uY9x7eaMoEMfn3OILqwTFYgaNp4llmguKI-C3_iA
  • zoom-domain-verification=4b2ef4e1-6dee-4483-9869-9bef353fd147
  • facebook-domain-verification=y7isfmi3kzyg1r4wophh9vyb6pgbda
  • google-site-verification=wdH5DTJTc9AYNwVunSVFeK0hYDGUIEOGb-RReU6pJlY
  • v=spf1 redirect=_spf.facebook.com
  • google-site-verification=A2WZWCNQHrGV_TWwKh6KHY90tY0SHZo_RnyMJoDaG0s

DKIM selectors

1 record
  • defaultdefault._domainkey.facebook.com
    • t=y; k=rsa; p=;

Probed with no records: selector1, selector2, google, 20230601, 20210112, k1, k2, s1, s2, dkim, mail

DMARC

1 record
v=DMARC1; p=reject; rua=mailto:a@dmarc.facebookmail.com; ruf=mailto:fb-dmarc@datafeeds.phishlabs.com; pct=100
v=DMARC1
Identifies this TXT record as a DMARC policy. Must be the first tag.
p=reject
Receivers refuse mail that fails DMARC outright.
rua=mailto:a@dmarc.facebookmail.com
Receivers send daily aggregate reports about passing and failing mail to a@dmarc.facebookmail.com.
ruf=mailto:fb-dmarc@datafeeds.phishlabs.com
Receivers may send per-message failure reports to fb-dmarc@datafeeds.phishlabs.com. Many receivers skip these for privacy reasons.
pct=100
The policy applies to all failing mail.
sp=rejectdefault
No sp= tag is published, so subdomains inherit the domain's p= policy.
adkim=rdefault
No adkim= tag is published, so DKIM alignment is relaxed: any subdomain of the From domain may sign.
aspf=rdefault
No aspf= tag is published, so SPF alignment is relaxed: the envelope sender may be any subdomain of the From domain.
Raw JSON

SSL & domain expiry

warnLast checked
Findings2 findings

Recommended (1)

  • The TLS certificate expires in 7 days (Sep 13, 2026).

    TLS certificate

    How to fix

    Renew the certificate before it expires and confirm auto-renewal is working.

Healthy (1)

  • Registration expiry is not published for this domain.

    Domain expiry

    The registry does not expose expiry data over RDAP.

Evidence

TLS certificate

port 443
Issued to
*.facebook.com
Issued by
DigiCert Inc
Valid from
Valid until
Days remaining
7 days
Verification
trusted

Registration

unpublished

The registry does not expose expiry data over RDAP.

Raw JSON

Generated by Internet Posture · internetposture.com