Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Oct 11, 2026 13:54 UTC · 7 checks · public report
Solid base — two policy steps remain.
winsauer.cc publishes DMARC with p=none — spoofed mail is monitored but not blocked.
Your SPF setup is working, but it uses a softer “fail” setting at the end, which means other mail servers are told to treat unknown senders with caution rather than reject them outright. This matters because it can leave a bit more room for spoofed email to slip through, though DMARC can still work with it. The fix, if you want stricter protection, is to switch to the harder reject setting only after you are sure every legitimate sender is included.
v=spf1 include:mailbox.org ~allYour domain has DMARC set up, but it is only in monitoring mode, so it is not actively blocking spoofed or fraudulent email. This matters because attackers can still try to send mail that looks like it came from your domain, which can hurt trust and deliverability. The fix is to change DMARC from monitoring to an enforcement mode so receivers know what to do with messages that fail authentication.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email hello@dnsdoctor.dev to have this page removed.
v=DMARC1;p=none;rua=mailto:postmaster@winsauer.cc