Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 23, 2026 01:51 UTC · 7 checks · public report
Solid base — two policy steps remain.
remax.com publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF setup is working, but it uses a softer “fail” setting at the end instead of a strict one. That means mail from unlisted senders is less strongly blocked, which can make spoofing a bit easier. The fix, if you want tighter protection, is to switch to the stricter mode only after you’ve confirmed every legitimate sender is already covered.
v=spf1 redirect=747i0evz._spf._d.mim.ecEdit your SPF record at Amazon Route 53 — step-by-step guide.
This means your email signing key for the DKIM selector named **selector2** is only 1024 bits, which is considered weak by modern standards. It matters because weaker keys are easier to attack and can reduce trust in your outgoing mail. The fix is to replace that DKIM key with a stronger one, usually 2048 bits, and then update your mail service to use the new key.
Publish your DKIM record at Amazon Route 53 — step-by-step guide.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 30-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email hello@dnsdoctor.dev to have this page removed.