DNS & email auth

warnLast checked
Findings5 findings

Recommended (2)

  • The record uses softfail (~all), which is weaker than fail (-all).

    SPF

    How to fix

    Move to -all once you're confident every legitimate sender is listed.

  • DMARC policy is p=none, so it monitors but does not enforce.

    DMARC

    How to fix

    Once your legitimate senders pass, move to p=quarantine and then p=reject.

Healthy (3)

  • 5 MX records found.

    MX
  • DKIM selector s1 has a healthy RSA key.

    DKIM

    s1 (s1._domainkey.modeeffect.com)

  • DKIM selector s2 has a healthy RSA key.

    DKIM

    s2 (s2._domainkey.modeeffect.com)

Evidence

MX

5 records
  • aspmx.l.google.compriority 1
  • alt1.aspmx.l.google.compriority 5
  • alt2.aspmx.l.google.compriority 5
  • alt3.aspmx.l.google.compriority 10
  • alt4.aspmx.l.google.compriority 10

SPF

7 of 10 lookups
DNS lookups7 / 10
modeeffect.com
include:mailgun.org
include:_spf.mailgun.org
include:_spf1.mailgun.org
include:_spf2.mailgun.org
include:_spf.eu.mailgun.org
include:emsd1.com
include:_spf.google.com

Root TXT

1 record
  • v=spf1 include:mailgun.org include:emsd1.com include:_spf.google.com ~all

DKIM selectors

2 records
  • s1s1._domainkey.modeeffect.com
    CNAME s1.domainkey.u1551233.wl234.sendgrid.net
    • k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAupHIFUn03L8Q2QWao9CF85XhujyrcvU6QydeUKz9Pdi1VMRRhTjDjRVcEhTxhV+rUWLO7iaClRA/RlZJvjIlz+tDLmsdky8CUoeB9KF4iF4OZs6Pi7FcsgGkhdYioOmCUCTsy1QD2Eti7EJ/bnqDkjIg2yTYGyqv/ws4R1vh+HXZbH2WHuc9AhELgiE2pPq2VvvRyygKsPPg4+HUlGOufas6w0Tt/3uQDd9PkrF1cqS6XyRgjfQBfVJJdmQsqb9aJh2aE3F+6e0h1bEWA/5WVlxPC4POmoCZ68xqqPA68zZYq9/weST0WF9tqwpuqoH/4fqfbuFaEaOjEuq4jr4+fwIDAQAB
  • s2s2._domainkey.modeeffect.com
    CNAME s2.domainkey.u1551233.wl234.sendgrid.net
    • k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAylFhSo+/0GIPVyzX7rYsav/2PkV+r4jWNvRbmSG4qyIiSVP1g1pb3NrHLwz0kMwNwC0UJylNtKkiOIxEnwyoOR69Wgatt434c/VWiKLxLlmmOUpzsbq9uL8+kTPeT1gK1z9euXY//N+bzD4O0riwES0iAaEoNqhvtPQpblNTjxiuPUu1v07daY8iOPi9sF1y5N84bPx2CV6Za6LxVCudMnKwmUqwfcldpMJUqRUxtEi8MovfmP1X9SJpCVsH3oxtmhh1QsfE5I8bhrumplnHS6bgxpNn5y29m2UcBQZcVSLhFAMXSZlEQQ1UwC6PzgmmXHtd39T8nT4Cf97LN0b90QIDAQAB

Probed with no records: selector1, selector2, google, 20230601, 20210112, k1, k2, default, dkim, mail

DMARC

1 record
v=DMARC1; p=none; pct=100; rua=mailto:weliketohelp@modeeffect.com
v=DMARC1
Identifies this TXT record as a DMARC policy. Must be the first tag.
p=none
Monitoring only: receivers deliver failing mail normally and just send reports.
pct=100
The policy applies to all failing mail.
rua=mailto:weliketohelp@modeeffect.com
Receivers send daily aggregate reports about passing and failing mail to weliketohelp@modeeffect.com.
sp=nonedefault
No sp= tag is published, so subdomains inherit the domain's p= policy.
adkim=rdefault
No adkim= tag is published, so DKIM alignment is relaxed: any subdomain of the From domain may sign.
aspf=rdefault
No aspf= tag is published, so SPF alignment is relaxed: the envelope sender may be any subdomain of the From domain.
Raw JSON