Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 25, 2026 14:37 UTC · 7 checks · public report
Solid base — four policy steps remain.
antel.com.uy publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF check is using a softer “fail” setting at the end, which means some mail that does not match the approved senders may still be treated as questionable rather than fully rejected. This matters because it gives spoofed email a better chance of slipping through, although it does not break DMARC by itself. The fix, if you want stricter protection, is to switch to a hard fail only after you’ve confirmed every legitimate sender is already included.
v=spf1 ip4:200.40.34.96/27 include:servers.mcsv.net include:sparkpostmail.com ~allThis means your email-signing key for the DKIM selector **k1** is only **1024 bits**, which is considered too weak by modern standards. A weaker key is easier to attack, so it can reduce trust in your outgoing mail and make it more likely to be rejected or treated as suspicious. The fix is to update DKIM for that selector to use a **stronger key**, typically **2048 bits**, and publish the new key in DNS.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 30-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email hello@dnsdoctor.dev to have this page removed.
Your domain has three mail servers listed, which means email for your domain is being routed through those servers. This matters because the MX records tell other mail systems where to deliver messages for you. If this is correct, no change is needed; if not, update the mail routing settings so they point to the right email provider or server.
mx01.antel.com.uy, mx02.antel.com.uy, mx03.antel.com.uyYour site’s TLS certificate will expire in 21 days, on 2026-10-16. This matters because visitors may start seeing browser security warnings, and some users or services may stop trusting the site. The fix is to renew or replace the certificate before that date and make sure the new certificate is installed correctly.
TLS certificate expires 2026-10-16