Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Aug 14, 2026 18:07 UTC · 7 checks · public report
Solid base — three policy steps remain.
ycombinator.com publishes DMARC with p=none — spoofed mail is monitored but not blocked.
v=spf1 include:_spf.google.com include:mailgun.org a:rsweb1-36.investorflow.com include:_spf.createsend.com include:servers.mcsv.net -allEdit your SPF record at Amazon Route 53 — step-by-step guide.
v=DMARC1; p=none; pct=100; sp=none; ruf=mailto:[email protected]; rua=mailto:[email protected]; aspf=r;_dmarc · Record type: · TTL: One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.
TXT3600v=DMARC1; p=quarantine; sp=none; ruf=mailto:[email protected]; rua=mailto:[email protected]; aspf=r; np=rejectApply this at Amazon Route 53 — step-by-step guide.
Your email authentication is using a DKIM key that is too short, which makes it weaker than recommended. This matters because weaker keys are easier to break, so email spoofing and tampering are harder to defend against. The fix is to replace that DKIM key with a stronger, longer key and update the DKIM setup for the affected selector.
Publish your DKIM record at Amazon Route 53 — step-by-step guide.