Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Oct 5, 2026 21:35 UTC · 7 checks · public report
Solid base — two policy steps remain.
oshwal.org publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF check is set to a softer “maybe not authorized” mode at the end, which is usually fine for email deliverability and still works for DMARC. The only downside is that it is a bit less strict, so spoofed mail is not blocked as firmly as it could be. If you want to harden it, change that final policy to the stricter version, but only after you’ve confirmed every legitimate sender is already included.
v=spf1 a mx ip4:87.106.100.170 include:dnsexit.com include:spf.mailigen.com include:spf.protection.outlook.com include:musing-brahmagupta.87-106-100-170.plesk.page include:ip87-106-100-170.pbiaas.com ~allEdit your SPF record at IONOS — step-by-step guide.
This means your email signature key is smaller than recommended, so it is easier to break than a modern one. If an attacker can forge that signature, your messages may be more likely to be spoofed or tampered with. The fix is to replace this DKIM selector with a stronger, modern key size and then update the DNS entry for that selector.
Publish your DKIM record at IONOS — step-by-step guide.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email hello@dnsdoctor.dev to have this page removed.