DNS & email auth

warnLast checked
Findings4 findings

Recommended (2)

  • The record uses softfail (~all), which is weaker than fail (-all).

    SPF
  • DMARC policy is p=none, so it monitors but does not enforce.

    DMARC

    Once your legitimate senders pass, move to p=quarantine and then p=reject.

Healthy (2)

  • 5 MX records found.

    MX
  • DKIM selector google has a healthy RSA key.

    DKIM

    google (google._domainkey.wemailyourbrand.com)

Evidence

MX

5 records
  • aspmx.l.google.compriority 1
  • alt1.aspmx.l.google.compriority 5
  • alt2.aspmx.l.google.compriority 5
  • alt3.aspmx.l.google.compriority 10
  • alt4.aspmx.l.google.compriority 10

Root TXT

6 records
  • pinterest-site-verification=2a55d9e271cfeeee13f63158d57c7ba8
  • v=spf1 include:_spf.google.com ~all
  • openai-domain-verification=dv-4oM1n8c6TCB0TJ5Ama4kFyCm
  • google-site-verification=mSrYrYUhnfRB4VRgTEeiJI0Dzt3dMNtLo46PoFZ5_kc
  • klaviyo-site-verification=T7dy5b
  • google-site-verification=xBAs32rxlxcaNLYgAciRsYcwXkK2W0Eu9VI5ZnzaWZs

DKIM selectors

1 record
  • selector1selector1._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

  • selector2selector2._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

  • googlegoogle._domainkey.wemailyourbrand.com
    • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwuVNNRxrxPEkqZL0fI1bakbvZsPxf/wNBJcVzhuUveXNAtOq3uvdnQsqKKPywOP7sg2TTQHV+MTEC5zF5fG+KOFs2bwZpbUPnfEwr2u+McGgsN8U5Eho21Y1hsU6938E2Bv0JMnQMZnKnMrWaXWZHkVwpHsxCItiQcFaqmd+IVbuZGgRIN0zD2YF2WjOtp3FZlAng23pUoif3Q5Qv7R14la/jvmhc7FdLCu6e59RDw8AvWn/v2bVHdSueHgmgXuDIUnr6TqzORwZ5j9Kv6FsBL4rq2trZm5DGUxn0NsXnNQhPk38BLFnQKjOLR/vxCMhZyHzjRETukF1/WAcFt4RUwIDAQAB
  • 2023060120230601._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

  • 2021011220210112._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

  • k1k1._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

  • k2k2._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

  • s1s1._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

  • s2s2._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

  • defaultdefault._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

  • dkimdkim._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

  • mailmail._domainkey.wemailyourbrand.com

    No TXT records returned for this selector.

DMARC

1 record
v=DMARC1; p=none; rua=mailto:postmaster@wemailyourbrand.com, mailto:dmarc@wemailyourbrand.com; pct=100; adkim=s; aspf=s
v=DMARC1
Identifies this TXT record as a DMARC policy. Must be the first tag.
p=none
Monitoring only: receivers deliver failing mail normally and just send reports.
rua=mailto:postmaster@wemailyourbrand.com, mailto:dmarc@wemailyourbrand.com
Receivers send daily aggregate reports about passing and failing mail to postmaster@wemailyourbrand.com, dmarc@wemailyourbrand.com.
pct=100
The policy applies to all failing mail.
adkim=s
Strict DKIM alignment: the DKIM signature's domain must exactly match the From domain.
aspf=s
Strict SPF alignment: the envelope sender must exactly match the From domain.
sp=nonedefault
No sp= tag is published, so subdomains inherit the domain's p= policy.
Raw JSON