Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 4, 2026 13:29 UTC · 7 checks · public report
Solid base — three policy steps remain.
cloudsales.app publishes DMARC with p=none — spoofed mail is monitored but not blocked.
v=spf1 include:_spf.mx.cloudflare.net include:sendersrv.com include:spf.mailjet.com include:mailgun.org ~allEdit your SPF record at Cloudflare — step-by-step guide.
Your domain has a DMARC setting, but it is only in monitoring mode, so it is not actually blocking fake or forged emails. This matters because attackers can still send messages that look like they came from your domain, which can hurt trust and increase phishing risk. To fix it, change the DMARC policy from monitoring only to an enforcing mode so email receivers are told to reject or quarantine suspicious mail.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.
v=DMARC1; p=none;Edit your DMARC record at Cloudflare — step-by-step guide.
This means your email-signing key for the DKIM selector **k1** is only **1024 bits**, which is considered too weak by modern standards. A weaker key is easier to attack, so it can reduce trust in your outgoing mail and make it more likely to be rejected or treated as suspicious. The fix is to update DKIM for that selector to use a **stronger key**, typically **2048 bits**, and publish the new key in DNS.
Publish your DKIM record at Cloudflare — step-by-step guide.