Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Jul 19, 2026 18:44 UTC · 7 checks · public report
Solid base — two policy steps remain.
apple.com publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF setting currently ends with a soft-fail rule, which means other mail servers are only told to treat unauthorized mail as suspicious rather than clearly reject it. This matters because it makes it easier for spoofed emails using your domain to get through or appear less clearly blocked. Once you’re sure every legitimate sender is included, change the last part of the SPF policy to a hard-fail rule so unauthorized mail is rejected instead of merely flagged.
v=spf1 include:_spf.apple.com include:_spf-txn.apple.com ~allThis means your email signature key is smaller than recommended, so it is easier to break than a modern one. If an attacker can forge that signature, your messages may be more likely to be spoofed or tampered with. The fix is to replace this DKIM selector with a stronger, modern key size and then update the DNS entry for that selector.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.