← Interactive report

brightorangethread.com

warnScanned ·
Summary

brightorangethread.com has warnings

0To fix now
2Recommended
6Healthy

DNS & email auth

warnLast checked
Findings6 findings

Recommended (2)

  • The record uses softfail (~all), which is weaker than fail (-all).

    SPF

    How to fix

    Move to -all once you're confident every legitimate sender is listed.

  • DKIM selector s2 uses a 1024-bit RSA key.

    DKIM

    s2 (s2._domainkey.brightorangethread.com)

    How to fix

    Rotate to an RSA key of at least 2048 bits.

Healthy (4)

  • 5 MX records found.

    MX
  • DKIM selector google has a healthy RSA key.

    DKIM

    google (google._domainkey.brightorangethread.com)

  • DKIM selector s1 has a healthy RSA key.

    DKIM

    s1 (s1._domainkey.brightorangethread.com)

  • DMARC policy is enforced with p=quarantine.

    DMARC

Evidence

MX

5 records
  • aspmx.l.google.compriority 1
  • alt1.aspmx.l.google.compriority 5
  • alt2.aspmx.l.google.compriority 5
  • alt3.aspmx.l.google.compriority 10
  • alt4.aspmx.l.google.compriority 10

SPF

3 of 10 lookups
DNS lookups3 / 10
brightorangethread.com
include:_spf.google.com
include:dc-aa8e722993._spfm.brightorangethread.com
include:_spf.google.com

Root TXT

3 records
  • google-site-verification=aoMMPRtIOYLRMReY5f51xupP8OTsxl0ojFguu1efj7A
  • google-site-verification=M70mdlrvr3Yi2rL1PE_LDiCz6doBUr-H99ssLM0zhNc
  • v=spf1 include:_spf.google.com include:dc-aa8e722993._spfm.brightorangethread.com ~all

DKIM selectors

3 records
  • googlegoogle._domainkey.brightorangethread.com
    • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmVhhnqnyTheI03OSfTF3fNvrrXZKKNdyUObbW2RgJBktWB02wG7HfjMjjx90SOXwCQAw7jBqigKImN8UVMHdkuP4aCWZ9hOHbe1NLUY3vHQW76ISfFHscOV9EX0Ic5Vqbl1pNWtPZyIl9M+3n9d1NJc2Br5MFM1jphdAjEij0fEPf+I0lsXgP0jKFYgRPDcTJiB/8RXq4Ty1g29QvvU+4lMRE+58ZtA9QUKWo0WoBYlesL5DtUyGlV/G0BAowq6b3oCp0TIAU2mGhhjoPuB4T+rnRl9p51NanQoLZNEMhpS0eP4TUy+kjU6fmXKVCkGJpwv24tdJS8wandoZRDwhHQIDAQAB
  • s1s1._domainkey.brightorangethread.com
    CNAME sg1.v15318018.c308464513.e.marketingautomation.services
    • k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtk2SZNl5cIntoEOL9ovx10U6CjmNyHY+9X2L2fwHFx8+Be+hGrOpqtBNv1NTa9gmu+AOzOQUuQmnVDHgI+uZq8x4CEHOS2tvLMEV5UrbObovSKl9UKeaSdyiCdfbdhqRNCm+ZDEqiZUntcqaRfZLzv1xH7NuWlYooFGHkJhsOIkinldUGxGYwnuvG0F3KzBYtHCi2qWaEzMqnTU+Jn4VI1Aa9K8261Kd45p6zyb8WKjd6tn2EhqML26beisRpxd35FfrnVyrziZiquyN+ULeyHM20NtTvIx37bKY+eAKb7CwqRvZhfnF1Sy5PBkcIsIXcRC61RQVAcLpW7YDqRkGjwIDAQAB
  • s2s2._domainkey.brightorangethread.com
    CNAME sg2.v15318018.c308464513.e.marketingautomation.services
    • k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQ5Zk3WBICE13NifBG2rJiWTSWwYYECwJA7dgCS2qJCgsKuybBGM/5NOtNXTqeVrtbSN9DHWiFoZA/4okBgsFOdTkQCDmvSO3UhPcubynF0agiMmxBPhMrvxosBnr6Ml9LapUPLCQiouSOwcFWPkf7RVa3fmOSUVIioHpuIbZ0KQIDAQAB

Probed with no records: selector1, selector2, 20230601, 20210112, k1, k2, default, dkim, mail

DMARC

1 record
v=DMARC1;p=quarantine; rua=mailto:re+41b966582fa6@inbound.dmarcdigests.com
v=DMARC1
Identifies this TXT record as a DMARC policy. Must be the first tag.
p=quarantine
Receivers treat failing mail with suspicion, typically sending it to spam.
rua=mailto:re+41b966582fa6@inbound.dmarcdigests.com
Receivers send daily aggregate reports about passing and failing mail to re+41b966582fa6@inbound.dmarcdigests.com.
sp=quarantinedefault
No sp= tag is published, so subdomains inherit the domain's p= policy.
pct=100default
No pct= tag is published, so the policy applies to all failing mail.
adkim=rdefault
No adkim= tag is published, so DKIM alignment is relaxed: any subdomain of the From domain may sign.
aspf=rdefault
No aspf= tag is published, so SPF alignment is relaxed: the envelope sender may be any subdomain of the From domain.
Raw JSON

SSL & domain expiry

passLast checked
Findings2 findings

Healthy (2)

  • The TLS certificate is valid until Oct 26, 2026.

    TLS certificate

    Issued by GlobalSign nv-sa.

  • Registration expiry is not published for this domain.

    Domain expiry

    The registry does not expose expiry data over RDAP.

Evidence

TLS certificate

port 443
Issued to
www.brightorangethread.com
Issued by
GlobalSign nv-sa
Valid from
Valid until
Days remaining
50 days
Verification
trusted

Registration

unpublished

The registry does not expose expiry data over RDAP.

Raw JSON

Generated by Internet Posture · internetposture.com