Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Jul 21, 2026 09:36 UTC · 7 checks · public report
Solid base — two policy steps remain.
spotify.com publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF setting is using a “soft fail” at the end, which means other mail servers are only told to be suspicious of unauthorized mail from your domain, not to reject it outright. This matters because spoofed or fake emails from your domain may be treated less strictly, which can hurt security and sender trust. The fix is to change the SPF policy to a strict reject-only end setting once you’ve confirmed every legitimate sender is already included.
v=spf1 ip4:80.76.146.172 ip4:80.76.146.173 include:_spf.google.com include:servers.mcsv.net include:_spf.salesforce.com include:_spf.netigate.se include:21894833.spf06.hubspotemail.net ~allEdit your SPF record at Google Cloud DNS — step-by-step guide.
Your email authentication is using a DKIM key that is too short, which makes it weaker than recommended. This matters because weaker keys are easier to break, so email spoofing and tampering are harder to defend against. The fix is to replace that DKIM key with a stronger, longer key and update the DKIM setup for the affected selector.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.