Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Jul 20, 2026 23:12 UTC · 7 checks · public report
Solid base — two policy steps remain.
harvard.edu publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:spf.mailjet.com ~allThis means your email signing key is too small, which makes it easier for attackers to break the protection that helps prove your messages are really from you. If it stays weak, email can be more vulnerable to spoofing or tampering. The fix is to replace the current DKIM key with a stronger one, usually by creating a new DKIM key pair with a larger key size and updating the signing setup to use it.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.