Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 8, 2026 15:24 UTC · 7 checks · public report
Solid base — one policy step remains.
crghostmaster.com publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF check is using a soft fail setting at the end, which means mail from servers not listed is not fully rejected. This is usually okay for DMARC, but it gives a weaker signal than a hard fail. To tighten security, switch to a hard fail only after you are sure every legitimate sender is included in your SPF setup.
v=spf1 +mx +a +ip4:168.235.116.112 +include:spf.leadconnectorhq.com +include:relay.mailchannels.net include:_spf.google.com ~allEdit your SPF record at Cloudflare — step-by-step guide.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.