Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Jul 21, 2026 09:37 UTC · 7 checks · public report
Solid base — two policy steps remain.
hotline.ua publishes DMARC with p=none — spoofed mail is monitored but not blocked.
Your SPF check is using a “soft fail” at the end, which tells receiving mail servers to be cautious but not strictly reject messages that fail the check. This matters because attackers can sometimes spoof your domain more easily when the policy is not enforced strictly. The fix is to change the ending to a strict reject setting, but only after you’ve confirmed every legitimate sender is already included in the SPF list.
v=spf1 ip4:77.222.150.16/28 ip4:93.183.199.240/28 ip4:86.111.89.50 ip4:31.42.176.254 include:_spf.google.com ~allEdit your SPF record at Cloudflare — step-by-step guide.
Your domain has DMARC set up, but it is only in monitoring mode, so it does not actually block or quarantine suspicious email. This matters because attackers can more easily spoof messages that look like they came from your domain, which can hurt trust and increase phishing risk. To fix it, change DMARC from monitoring-only to an enforcement mode so email that fails authentication is handled instead of just reported.
v=DMARC1; p=none; rua=mailto:[email protected]One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.
_dmarc · Record type: TXT · TTL: 3600v=DMARC1; p=quarantine; rua=mailto:[email protected]Apply this at Cloudflare — step-by-step guide.