Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Oct 2, 2026 20:30 UTC · 7 checks · public report
One finding blocks deliverability.
bradleyripple.com has no enforceable DMARC policy, so mail that forges its domain is not blocked at the recipient.
Your domain does not have a DMARC policy set up, which means receiving mail servers have no clear instructions for what to do with messages that claim to come from your domain. This matters because it makes your domain easier to impersonate in phishing and spoofing attacks, and it also reduces your control and visibility over email delivery. The fix is to publish a DMARC record in your DNS for the domain.
_dmarc · Record type: TXT · TTL: 3600v=DMARC1; p=none; np=rejectApply this at Cloudflare — step-by-step guide.
Your SPF check is using a soft-fail setting at the end, which means other servers are told to treat unexpected senders as suspicious but not always block them. This matters because it makes your domain a little easier to spoof, though it still works for DMARC. The fix, if you want to tighten security, is to switch to a hard-fail setting only after you’re sure every legitimate sender is included.
v=spf1 include:_spf.mx.cloudflare.net ~allOne send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email hello@dnsdoctor.dev to have this page removed.
Edit your SPF record at Cloudflare — step-by-step guide.
Publish your DKIM record at Cloudflare — step-by-step guide.