DNS & email auth

warnLast checked
Findings5 findings

Recommended (1)

  • DKIM selector k1 uses a 1024-bit RSA key.

    DKIM

    k1 (k1._domainkey.scandiweb.com)

    How to fix

    Rotate to an RSA key of at least 2048 bits.

Healthy (4)

  • 5 MX records found.

    MX
  • SPF record is valid, using 6 of 10 DNS lookups.

    SPF
  • DKIM selector google has a healthy RSA key.

    DKIM

    google (google._domainkey.scandiweb.com)

  • DMARC policy is enforced with p=reject.

    DMARC

Evidence

MX

5 records
  • aspmx.l.google.compriority 1
  • alt1.aspmx.l.google.compriority 5
  • alt2.aspmx.l.google.compriority 5
  • alt3.aspmx.l.google.compriority 10
  • alt4.aspmx.l.google.compriority 10

SPF

6 of 10 lookups
DNS lookups6 / 10
scandiweb.com
include:_spf.google.com
include:servers.mcsv.net
include:_spf.salesforce.com
include:emsd1.com
include:25724996.spf08.hubspotemail.net

Root TXT

9 records
  • google-site-verification=Oj2IgpPTpFo8vh3tZzgneNVub4K8yV6U6-jD1cW4yLQ
  • google-site-verification=X7bjBFUilFhUxFKg3yNUkk24bgf9Ahbf4ow1OxNtbgY
  • v=spf1 include:_spf.google.com include:servers.mcsv.net include:_spf.salesforce.com include:emsd1.com include:25724996.spf08.hubspotemail.net -all
  • 1password-site-verification=TKC3QMQGENHDBIWTLZV2X3EFIU
  • apple-domain-verification=f9TNERLJnjoMsDA1
  • atlassian-domain-verification=DyQ1dJckOAHwKAafnu2UWwlev7CRHDm/DBA6SJRbwdL26vSlItqjKBbqbMv65rOc
  • atlassian-domain-verification=kUKmFqmZtWYQJpD7iFqFWmyEDScx0f/uxKf6pArYAO2Sv8rpCyUyngo+CdG4OGDw
  • atlassian-sending-domain-verification=b754eafb-aff3-4b42-bf39-15d6665b030d
  • cursor-domain-verification-tzrjjt=Ca20Aos7UEMmWswDzwPLHJSNa

DKIM selectors

2 records
  • googlegoogle._domainkey.scandiweb.com
    • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAorwzXAySjpXkc+47tT3BTkmloTTWlqIMTAQd7N1ODxzQty3HsVcwBv1EDEHt4hc+tbUsA6mIB0cU8fdI/WWA55oRfXhXse+7kXbTEetX2k+W6nZu5zJK0VKJWUdpMlKM2OSKwISXRd3YNsG/43LQ1HH33nIlnWORqgmtQhPnfW9jGsUT0OVHxOtoRREgPaiD/O/A42iZOw2mO5/5ijoAWVJglQpe00VOwyMDWHDQmvlnLNQ+H+mzI7KIczB9r1mxkUHv+KVjGRFd0HFSKwCEGq0FcQqgbQx2HsXVWC/0moahdBvrHL0+mvaS1i7BFeA0h7GqBZmhuN9UTwazdAGtOwIDAQAB
  • k1k1._domainkey.scandiweb.com
    CNAME dkim.mcsv.net
    • k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUoNyIR4Bn84LVcfZE20rmDeXQblIupNWBqLXM1Q+VieI/eZu/7k9/vOkLSaQQdml4Cv8lb3PcnluMVIhQIDAQAB;

Probed with no records: selector1, selector2, 20230601, 20210112, k2, s1, s2, default, dkim, mail

DMARC

1 record
v=DMARC1; p=reject; rua=mailto:f2c98b1a81354aa8bcefab1f58683e8b@dmarc-reports.cloudflare.net;
v=DMARC1
Identifies this TXT record as a DMARC policy. Must be the first tag.
p=reject
Receivers refuse mail that fails DMARC outright.
rua=mailto:f2c98b1a81354aa8bcefab1f58683e8b@dmarc-reports.cloudflare.net
Receivers send daily aggregate reports about passing and failing mail to f2c98b1a81354aa8bcefab1f58683e8b@dmarc-reports.cloudflare.net.
sp=rejectdefault
No sp= tag is published, so subdomains inherit the domain's p= policy.
pct=100default
No pct= tag is published, so the policy applies to all failing mail.
adkim=rdefault
No adkim= tag is published, so DKIM alignment is relaxed: any subdomain of the From domain may sign.
aspf=rdefault
No aspf= tag is published, so SPF alignment is relaxed: the envelope sender may be any subdomain of the From domain.
Raw JSON