Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 30, 2026 12:08 UTC · 7 checks · public report
Solid base — one policy step remains.
myaccept.com publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF setup is allowing mail from servers that are not explicitly approved, but it marks them as soft failures instead of outright rejects. This usually still works with DMARC, but it is less strict and can leave a bit more room for spoofed mail. The fix is to switch to a stricter “hard fail” policy only after you are sure every legitimate sender is already included in the SPF list.
v=spf1 include:_spf.protonmail.ch ~allEdit your SPF record at Cloudflare — step-by-step guide.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email hello@dnsdoctor.dev to have this page removed.