Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 2, 2026 08:38 UTC · 7 checks · public report
Solid base — two policy steps remain.
mcj.sk publishes DMARC with p=none — spoofed mail is monitored but not blocked.
Your SPF setup is currently using a softer “allow with caution” rule at the end, which means some mail servers may treat messages from unlisted senders as suspicious rather than clearly rejecting them. This can make it easier for spoofed email to slip through or be handled inconsistently by recipient servers. The fix is to change that ending to a stricter reject rule once you’re sure every legitimate sender is already covered.
v=spf1 include:_spf.mailersend.net redirect=icloud.comEdit your SPF record at Cloudflare — step-by-step guide.
Your domain has DMARC set up, but it is only in monitoring mode, so it is not actively stopping fake or spoofed email yet. This matters because attackers can still impersonate your domain in email, which can hurt trust and deliverability. The fix is to change DMARC from monitoring to a protective mode so unauthorized messages are rejected or quarantined instead of just reported.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.
v=DMARC1; p=none; rua=mailto:[email protected]_dmarc · Record type: TXT · TTL: 3600v=DMARC1; p=quarantine; rua=mailto:[email protected]; np=rejectApply this at Cloudflare — step-by-step guide.
Publish your DKIM record at Cloudflare — step-by-step guide.