Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 27, 2026 21:28 UTC · 7 checks · public report
Solid base — two policy steps remain.
cocsd.k12.az.us publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF setup is working, but it ends with a softer “fail” setting, which means mail from unlisted senders is not fully blocked. This matters because it can make spoofed email slightly easier to slip through, though it is still acceptable for DMARC to work. If you want to tighten it later, change that ending to a hard fail only after you are sure every legitimate sender is already included.
v=spf1 include:sendgrid.net include:_spf.google.com include:amazonses.com ip4:134.114.4.180 ip4:134.114.5.99/32 ip4:134.114.4.175 ip4:134.114.4.176 mx:sisk12.com ~allYour email authentication is using a DKIM key that is too short, which makes it weaker than recommended. This matters because weaker keys are easier to break, so email spoofing and tampering are harder to defend against. The fix is to replace that DKIM key with a stronger, longer key and update the DKIM setup for the affected selector.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 30-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email hello@dnsdoctor.dev to have this page removed.