Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Jul 19, 2026 15:57 UTC · 7 checks · public report
Solid base — two policy steps remain.
gmail.com publishes DMARC with p=none — spoofed mail is monitored but not blocked.
Your domain’s email policy is still in a “soft fail” mode, which means other mail servers may treat messages from unauthorized senders as suspicious but still accept them. This matters because it makes it easier for spoofed or forged mail to get through, which can hurt deliverability and trust. The fix is to tighten the SPF policy from soft fail to hard fail after you’ve confirmed every legitimate sender is already included.
v=spf1 redirect=_spf.google.comYour domain has a DMARC policy in place, but it is set to monitoring only, so it is not actively stopping spoofed or fake email. This matters because attackers can more easily pretend to send mail from your domain, which can hurt trust and increase phishing risk. To fix it, change the DMARC policy from monitoring to an enforcement mode that tells receiving mail servers to reject or quarantine messages that fail authentication.
v=DMARC1; p=none; sp=quarantine; rua=mailto:[email protected]One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.
_dmarc · Record type: TXT · TTL: 3600v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:[email protected]