Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Aug 31, 2026 03:08 UTC · 7 checks · public report
Solid base — one policy step remains.
spf.guru publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF setup currently uses a soft-fail rule at the end, which tells receiving mail servers to treat unlisted senders as suspicious but not outright reject them. That matters because it makes it easier for spoofed email to slip through or be handled inconsistently. Once you’re sure every legitimate sender is included, change the ending to a hard-fail rule so unauthorized mail is rejected.
v=spf1 include:i.%{ir}._d.c8o3.%{d}.my.spf.guru ~include:f.%{ir}._d.c8o3.%{d}.my.spf.guru ~allEdit your SPF record at Cloudflare — step-by-step guide.
Publish your DKIM record at Cloudflare — step-by-step guide.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.