Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Sep 2, 2026 21:41 UTC · 7 checks · public report
Solid base — three policy steps remain.
vicinn.com publishes DMARC with p=none — spoofed mail is monitored but not blocked.
Your SPF setup is warning because it ends with a soft-fail rule, which tells receiving mail servers to be cautious about messages that are not on the approved list. This matters because spoofed email can be harder to block, so some fake mail may still be treated as suspicious rather than clearly rejected. The fix is to change the final SPF policy to a hard-fail rule after you have confirmed every legitimate sender is included.
v=spf1 +ip4:216.36.128.242 +ip4:52.26.18.86 include:_spf.google.com include:_spf.createsend.com ~allYour domain has DMARC set up, but it is only in monitoring mode, so it does not stop fraudulent emails from being used in your name. This matters because attackers can spoof your domain more easily, which can hurt trust and increase phishing risk. The fix is to change DMARC from monitoring-only to an enforcement mode so failing messages are rejected or quarantined instead of just reported.
v=DMARC1; p=none; rua=mailto:[email protected]One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.
_dmarc · Record type: TXT · TTL: 3600v=DMARC1; p=quarantine; rua=mailto:[email protected]; np=rejectYour email authentication is using a DKIM key that is too short, which makes it weaker than recommended. This matters because weaker keys are easier to break, so email spoofing and tampering are harder to defend against. The fix is to replace that DKIM key with a stronger, longer key and update the DKIM setup for the affected selector.