Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 2, 2026 21:47 UTC · 7 checks · public report
One finding blocks deliverability.
genesishospitality.ca publishes DMARC with p=none — spoofed mail is monitored but not blocked.
Your website’s TLS certificate has expired, which means visitors may see security warnings and their browser may treat the site as unsafe. This can hurt trust and can also break secure connections for some users and services. The fix is to renew and replace the expired certificate on the site’s server before it expires again.
domain registration expires 2026-09-17; TLS certificate expires 2024-01-20Your SPF setup is currently in “soft fail” mode, which tells receiving mail servers to treat unlisted senders with caution instead of rejecting them outright. This matters because it makes it easier for spoofed email to slip through or be handled inconsistently. Once you’re sure every legitimate sender is included, change the policy to a strict fail so unauthorized mail is rejected.
v=spf1 ip4:207.219.3.8 include:_spf.google.com ~allEdit your SPF record at Amazon Route 53 — .
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.
DMARC is set up, but it is only in monitoring mode, so it does not stop fake or spoofed emails from using your domain. That matters because scammers can more easily impersonate your business, which can hurt trust and deliverability. The fix is to change DMARC from monitoring-only to an enforcement mode so mail that fails checks is treated according to your policy.
v=DMARC1; p=none; rua=mailto:[email protected]_dmarc · Record type: TXT · TTL: 3600v=DMARC1; p=quarantine; rua=mailto:[email protected]; np=rejectApply this at Amazon Route 53 — step-by-step guide.
Your email authentication is using a DKIM key that is too short, which makes it weaker than recommended. This matters because weaker keys are easier to break, so email spoofing and tampering are harder to defend against. The fix is to replace that DKIM key with a stronger, longer key and update the DKIM setup for the affected selector.
Publish your DKIM record at Amazon Route 53 — step-by-step guide.