DNS & email auth

warnLast checked
Findings5 findings

Recommended (3)

  • The record uses softfail (~all), which is weaker than fail (-all).

    SPF

    How to fix

    Move to -all once you're confident every legitimate sender is listed.

  • DMARC policy is p=none, so it monitors but does not enforce.

    DMARC

    How to fix

    Once your legitimate senders pass, move to p=quarantine and then p=reject.

  • The record has no rua= aggregate reporting address, so no one is told when DMARC fails.

    DMARC

    How to fix

    Add rua=mailto:you@example.com to the record to receive daily aggregate reports from receivers.

Healthy (2)

  • 2 MX records found.

    MX
  • DKIM selector s1 has a healthy RSA key.

    DKIM

    s1 (s1._domainkey.profstep.com)

Evidence

MX

2 records
  • mxa.eu.mailgun.orgpriority 10
  • mxb.eu.mailgun.orgpriority 10

SPF

3 of 10 lookups
DNS lookups3 / 10
profstep.com
include:_spf.google.com
include:eu.mailgun.org
include:_spf.eu.mailgun.org

Root TXT

3 records
  • google-site-verification=wQYmGHHBq9wU11EEaZGMOwW1bkuM4aG5oiC7YK9udp8
  • v=spf1 include:_spf.google.com include:eu.mailgun.org ~all
  • google-site-verification=2z_gIaaTrYe0AsKlngfpOso9c7m_xHvEi7oFduwqgxU

DKIM selectors

1 record
  • 2023060120230601._domainkey.profstep.com

    No TXT records returned for this selector.

    CNAME lookup error: queryCname ESERVFAIL 20230601._domainkey.profstep.com

  • s1s1._domainkey.profstep.com
    • k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5kr4lSoPnFmOTqcZ4TEaKElMb/X95aebUXFfbgnIAoON8VVrC8lWH/XU2F5Eowkbq5utWw/ls414dl+d89w+bmGToxhzxOlz0uqEk37wDRX94LRhnVpCSrQ21+pwCSHVtq5zlDbHnMQ03PY4sxEw6sdOyuQfbMPA9BXoejxXA1YJKyLHbeg1iM9HP1rfm7Let2Q03yOoaHb2pi+hFpF79rdztza5hn3YYaAeHgC892F5E/N9YQxqAyqxmxptkJx3218QzvyeMpsAVFC7G8ARtBb11PFD92dw2Cl/e6tRb7D1O2z95SN6Wrim+LWYqZq3Duthnrswg3S0yDQOeXTw0QIDAQAB

Probed with no records: selector1, selector2, google, 20210112, k1, k2, s2, default, dkim, mail

DMARC

1 record
v=DMARC1; p=none;
v=DMARC1
Identifies this TXT record as a DMARC policy. Must be the first tag.
p=none
Monitoring only: receivers deliver failing mail normally and just send reports.
sp=nonedefault
No sp= tag is published, so subdomains inherit the domain's p= policy.
pct=100default
No pct= tag is published, so the policy applies to all failing mail.
adkim=rdefault
No adkim= tag is published, so DKIM alignment is relaxed: any subdomain of the From domain may sign.
aspf=rdefault
No aspf= tag is published, so SPF alignment is relaxed: the envelope sender may be any subdomain of the From domain.
Raw JSON