DNS & email auth

warnLast checked
Findings7 findings

Recommended (3)

  • The record uses softfail (~all), which is weaker than fail (-all).

    SPF

    How to fix

    Move to -all once you're confident every legitimate sender is listed.

  • DKIM selector s2 uses a 1024-bit RSA key.

    DKIM

    s2 (s2._domainkey.gettheclicks.com)

    How to fix

    Rotate to an RSA key of at least 2048 bits.

  • DMARC policy is p=none, so it monitors but does not enforce.

    DMARC

    How to fix

    Once your legitimate senders pass, move to p=quarantine and then p=reject.

Healthy (4)

  • 5 MX records found.

    MX
  • DKIM selector google has a healthy RSA key.

    DKIM

    google (google._domainkey.gettheclicks.com)

  • DKIM selector k2 has a healthy RSA key.

    DKIM

    k2 (k2._domainkey.gettheclicks.com)

  • DKIM selector s1 has a healthy RSA key.

    DKIM

    s1 (s1._domainkey.gettheclicks.com)

Evidence

MX

5 records
  • aspmx.l.google.compriority 1
  • alt1.aspmx.l.google.compriority 5
  • alt2.aspmx.l.google.compriority 5
  • alt3.aspmx.l.google.compriority 10
  • alt4.aspmx.l.google.compriority 10

SPF

1 of 10 lookups
DNS lookups1 / 10
gettheclicks.com
include:_spf.google.com

Root TXT

3 records
  • v=spf1 include:_spf.google.com ip4:159.135.227.78 ~all
  • google-site-verification=riGewa26R3BQfxa73cl3e96dhUeG8Mlupm_Je_Q24BE
  • twilio-domain-verification=684278148d4bb83a46a2cab0f7aa7b61

DKIM selectors

4 records
  • googlegoogle._domainkey.gettheclicks.com
    • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtAUnrG6bJIavre5rVVXwrOBSyktXTJPTuiwzMXyWSEo6VMSPdkuE+e3ftiVbp55rVbgvZ+I1n7k+Kw+5VEz6btviwe/yKxXgxqK98kkYReuxNAEWJUJnMltR+1F1nmcDJEL7QzyAOcXUMymhvJ6LHqHdbAg+MkzTGkhPRBfVIPFbd3puD4wDQZG9bNKgd/GeJdxxLhKQSGxvRshh5DbUjxQ1fsqqSg8oc44gVTGp3a6FRreLVwJWKfkkWnJjbYRFAYPyIKYvFn+QbtVqScw6mmOFIHekoMn1u95MPgUcp4VF8Prqx2ULwqyKRTVZx/MEzT/J7Y238hdhiqmjfPZRSQIDAQAB
  • k2k2._domainkey.gettheclicks.com
    CNAME dkim2.mcsv.net
    • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA0b90ObWaLDc+i9MtTNmGeWO009hr20fIxhGg6XBT2kjZ1DTThopSe1nAndsupmcBwlQ5Q6LJ+ZAxLcujnPIxM0ZBLmgpkv8u6RfY4eFP8OLvdAW3oSuB0DyLDigQX4Sj8wBO4YIdQH6AAmBeOsidsKAFNFUCpc3vCxtBDR12U+cBg724l3sBkMQ8evnz6idnqxq9QAVYh8k4kJ+RP+6cqTdy7LjIm8xY/bQNpQIpGUAuDo2DjLcCDun9DAI4Q/3z+Q0o9QuQIDAQAB;
  • s1s1._domainkey.gettheclicks.com
    CNAME s1.domainkey.u2309499.wl250.sendgrid.net
    • k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2nhy+QNv1KEbuyoSk5hA7eDvnQGGJepjL4/ZZ06pfyhUNALK2JaBl/NlPo13U9dZPJtfVc+AU1Zg9pC2++IIK+YPD3a3UC3hunC8pthZT27BaOHrBgaGyDJuhFmGFaqoVPSBV57Td9vIXCsp9o7lxrrl/BWcJsym1vpoE5KlCPCLuZ8KZr7mJzkwAB+aw7EVrrMJ/LemDcFG/QOmI8/FDSpl5xH4H1zbPCekeLXuryWKNoz9Cgnhf2Y8tyYUDRn1lCKlmznSSyohW0f2ofCZlzkhLua62X4G5eafHLfexiD5S8af7Y5UPynvgJFE6Drzyqbet9bEaGrZdkpLb3sHOwIDAQAB
  • s2s2._domainkey.gettheclicks.com
    CNAME s2.domainkey.u2309499.wl250.sendgrid.net
    • k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCj2M0V5NJN/XwZagEsvlkXb+SNZSN17l1YMvcLCdt8/WGanHryZZFpbWghQMpwPAyHPi+UynL2dsgOgBaRwPTaEjiB7TNaBCZAIN1gSruOd7kGRuEb+01WcJqKBeoNxMgaboc3bF3VLTo9VpOP3rZpJDWl/18afq2/sNLit7EP6wIDAQAB

Probed with no records: selector1, selector2, 20230601, 20210112, k1, default, dkim, mail

DMARC

1 record
v=DMARC1; p=none; rua=mailto:domains@gettheclicks.com; ruf=mailto:domains@gettheclicks.com; sp=none; fo=1
v=DMARC1
Identifies this TXT record as a DMARC policy. Must be the first tag.
p=none
Monitoring only: receivers deliver failing mail normally and just send reports.
rua=mailto:domains@gettheclicks.com
Receivers send daily aggregate reports about passing and failing mail to domains@gettheclicks.com.
ruf=mailto:domains@gettheclicks.com
Receivers may send per-message failure reports to domains@gettheclicks.com. Many receivers skip these for privacy reasons.
sp=none
Policy for subdomains, overriding p=. Monitoring only: receivers deliver failing mail normally and just send reports.
fo=1
Controls when failure reports are generated, e.g. 1 asks for a report when any underlying check fails.
pct=100default
No pct= tag is published, so the policy applies to all failing mail.
adkim=rdefault
No adkim= tag is published, so DKIM alignment is relaxed: any subdomain of the From domain may sign.
aspf=rdefault
No aspf= tag is published, so SPF alignment is relaxed: the envelope sender may be any subdomain of the From domain.
Raw JSON