Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Oct 10, 2026 18:56 UTC · 7 checks · public report
Solid base — two policy steps remain.
tow411.net publishes DMARC with p=none — spoofed mail is monitored but not blocked.
Your SPF setup is working, but it ends with a softer fallback that tells receiving mail servers to be cautious with messages from senders not listed there. This usually does not break delivery, but it is less strict than it could be and gives spoofed mail a slightly better chance of slipping through. The fix is to switch to a stricter fallback only after you are sure every legitimate email sender is included in the allowed list.
v=spf1 a mx include:_spf.perfora.net include:_spf.kundenserver.de include:amazonses.com include:sendgrid.net include:email-od.com include:_spf.maileroo.com a:email.tow411.net ~allEdit your SPF record at IONOS — step-by-step guide.
DMARC is set up, but it is only in monitoring mode, so it does not block suspicious email that claims to be from your domain. This matters because it leaves your domain more exposed to spoofing and phishing. The fix is to change DMARC from monitoring to an enforcement mode so mail that fails authentication is rejected or quarantined.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email hello@dnsdoctor.dev to have this page removed.
v=DMARC1; p=none; rua=mailto:19054d85874f.a@dmarcinput.com; ruf=mailto:19054d85874f.f@dmarcinput.com; sp=none; fo=1Edit your DMARC record at IONOS — step-by-step guide.