Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Jul 21, 2026 20:07 UTC · 7 checks · public report
Solid base — one policy step remains.
cloudflare.com publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
This means your email-signing key for the DKIM selector **k1** is only **1024 bits**, which is considered too weak by modern standards. A weaker key is easier to attack, so it can reduce trust in your outgoing mail and make it more likely to be rejected or treated as suspicious. The fix is to update DKIM for that selector to use a **stronger key**, typically **2048 bits**, and publish the new key in DNS.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.