Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 22, 2026 21:16 UTC · 7 checks · public report
Solid base — two policy steps remain.
sniffies.com publishes DMARC with p=none — spoofed mail is monitored but not blocked.
Your SPF setup is allowing mail that doesn’t match your approved senders to be treated as “neutral” instead of clearly rejected. That still works for DMARC, but it makes spoofing easier and gives less protection against fake messages. If you want to tighten it, change the policy so only the senders you trust are allowed, and switch to a stricter reject setting only after you’ve confirmed every legitimate sender is listed.
v=spf1 include:mail.zendesk.com ?allEdit your SPF record at Cloudflare — step-by-step guide.
DMARC is set up, but it is only in monitoring mode, so it is not actually blocking fake emails that use your domain. That matters because scammers can more easily spoof your address, which can hurt trust and deliverability. The fix is to change the DMARC policy from monitoring only to an enforcement mode so providers can reject or quarantine suspicious mail.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 30-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email hello@dnsdoctor.dev to have this page removed.
v=DMARC1; p=none; rua=mailto:contact@sniffies.comEdit your DMARC record at Cloudflare — step-by-step guide.