DNS & email auth

warnLast checked
Findings6 findings

Recommended (2)

  • The record uses softfail (~all), which is weaker than fail (-all).

    SPF

    How to fix

    Move to -all once you're confident every legitimate sender is listed.

  • DKIM selector s2 uses a 1024-bit RSA key.

    DKIM

    s2 (s2._domainkey.brightorangethread.com)

    How to fix

    Rotate to an RSA key of at least 2048 bits.

Healthy (4)

  • 5 MX records found.

    MX
  • DKIM selector google has a healthy RSA key.

    DKIM

    google (google._domainkey.brightorangethread.com)

  • DKIM selector s1 has a healthy RSA key.

    DKIM

    s1 (s1._domainkey.brightorangethread.com)

  • DMARC policy is enforced with p=quarantine.

    DMARC

Evidence

MX

5 records
  • aspmx.l.google.compriority 1
  • alt1.aspmx.l.google.compriority 5
  • alt2.aspmx.l.google.compriority 5
  • alt3.aspmx.l.google.compriority 10
  • alt4.aspmx.l.google.compriority 10

SPF

3 of 10 lookups
DNS lookups3 / 10
brightorangethread.com
include:_spf.google.com
include:dc-aa8e722993._spfm.brightorangethread.com
include:_spf.google.com

Root TXT

3 records
  • google-site-verification=M70mdlrvr3Yi2rL1PE_LDiCz6doBUr-H99ssLM0zhNc
  • v=spf1 include:_spf.google.com include:dc-aa8e722993._spfm.brightorangethread.com ~all
  • google-site-verification=aoMMPRtIOYLRMReY5f51xupP8OTsxl0ojFguu1efj7A

DKIM selectors

3 records
  • googlegoogle._domainkey.brightorangethread.com
    • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmVhhnqnyTheI03OSfTF3fNvrrXZKKNdyUObbW2RgJBktWB02wG7HfjMjjx90SOXwCQAw7jBqigKImN8UVMHdkuP4aCWZ9hOHbe1NLUY3vHQW76ISfFHscOV9EX0Ic5Vqbl1pNWtPZyIl9M+3n9d1NJc2Br5MFM1jphdAjEij0fEPf+I0lsXgP0jKFYgRPDcTJiB/8RXq4Ty1g29QvvU+4lMRE+58ZtA9QUKWo0WoBYlesL5DtUyGlV/G0BAowq6b3oCp0TIAU2mGhhjoPuB4T+rnRl9p51NanQoLZNEMhpS0eP4TUy+kjU6fmXKVCkGJpwv24tdJS8wandoZRDwhHQIDAQAB
  • s1s1._domainkey.brightorangethread.com
    CNAME sg1.v15318018.c308464513.e.marketingautomation.services
    • k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtk2SZNl5cIntoEOL9ovx10U6CjmNyHY+9X2L2fwHFx8+Be+hGrOpqtBNv1NTa9gmu+AOzOQUuQmnVDHgI+uZq8x4CEHOS2tvLMEV5UrbObovSKl9UKeaSdyiCdfbdhqRNCm+ZDEqiZUntcqaRfZLzv1xH7NuWlYooFGHkJhsOIkinldUGxGYwnuvG0F3KzBYtHCi2qWaEzMqnTU+Jn4VI1Aa9K8261Kd45p6zyb8WKjd6tn2EhqML26beisRpxd35FfrnVyrziZiquyN+ULeyHM20NtTvIx37bKY+eAKb7CwqRvZhfnF1Sy5PBkcIsIXcRC61RQVAcLpW7YDqRkGjwIDAQAB
  • s2s2._domainkey.brightorangethread.com
    CNAME sg2.v15318018.c308464513.e.marketingautomation.services
    • k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQ5Zk3WBICE13NifBG2rJiWTSWwYYECwJA7dgCS2qJCgsKuybBGM/5NOtNXTqeVrtbSN9DHWiFoZA/4okBgsFOdTkQCDmvSO3UhPcubynF0agiMmxBPhMrvxosBnr6Ml9LapUPLCQiouSOwcFWPkf7RVa3fmOSUVIioHpuIbZ0KQIDAQAB

Probed with no records: selector1, selector2, 20230601, 20210112, k1, k2, default, dkim, mail

DMARC

1 record
v=DMARC1;p=quarantine; rua=mailto:re+41b966582fa6@inbound.dmarcdigests.com
v=DMARC1
Identifies this TXT record as a DMARC policy. Must be the first tag.
p=quarantine
Receivers treat failing mail with suspicion, typically sending it to spam.
rua=mailto:re+41b966582fa6@inbound.dmarcdigests.com
Receivers send daily aggregate reports about passing and failing mail to re+41b966582fa6@inbound.dmarcdigests.com.
sp=quarantinedefault
No sp= tag is published, so subdomains inherit the domain's p= policy.
pct=100default
No pct= tag is published, so the policy applies to all failing mail.
adkim=rdefault
No adkim= tag is published, so DKIM alignment is relaxed: any subdomain of the From domain may sign.
aspf=rdefault
No aspf= tag is published, so SPF alignment is relaxed: the envelope sender may be any subdomain of the From domain.
Raw JSON