Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 27, 2026 21:30 UTC · 7 checks · public report
Solid base — two policy steps remain.
starboundaviator.com publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF setup is working, but it uses a softer ending that tells receiving mail servers to be cautious rather than treat unauthorized senders as definite failures. This matters because it can make it easier for spoofed email to slip through or be handled inconsistently. If you want tighter protection, change it to the stricter ending only after you’ve confirmed every legitimate service that sends mail for your domain is included.
v=spf1 include:simplelogin.co ~allEdit your SPF record at Namecheap — step-by-step guide.
This means your domain’s DKIM email signature is using a 1024-bit key, which is considered weak by modern security standards. It matters because weaker keys are easier to attack, and that can reduce trust in your outgoing mail or make it more likely to be rejected. The fix is to replace it with a stronger DKIM key and update the mail service to use the new selector/key.
Publish your DKIM record at Namecheap — step-by-step guide.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 30-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email hello@dnsdoctor.dev to have this page removed.