A
Scanned 23 days ago. Re-scan for a fresh result after a fix.
Issues to fix
- warnMX host mxa.global.inbound.cf-emailsecurity.net (141.101.90.40) has no PTR record; many receivers reject senders without reverse DNS.→
- warnMX host mxb.global.inbound.cf-emailsecurity.net (141.101.90.40) has no PTR record; many receivers reject senders without reverse DNS.→
- warnMX host mxb-canary.global.inbound.cf-emailsecurity.net (172.65.65.66) has no PTR record; many receivers reject senders without reverse DNS.→
- warnMX host mxa-canary.global.inbound.cf-emailsecurity.net (172.65.65.66) has no PTR record; many receivers reject senders without reverse DNS.→
- warnSelector mandrill key is ~1024-bit; rotate to 2048-bit.→
- warnSelector k1 key is ~1024-bit; rotate to 2048-bit.→
- warnpct=100 is deprecated in DMARCbis; apply the policy to all mail.→
- warnNo TLS-RPT reporting address; TLS delivery failures go unreported.→
Results
01Mail exchangers (MX)A
pass
4 MX record(s) found.
records
| preference | exchange | ttl |
|---|---|---|
| 5 | mxa-canary.global.inbound.cf-emailsecurity.net | 1096 |
| 5 | mxb-canary.global.inbound.cf-emailsecurity.net | 1096 |
| 10 | mxa.global.inbound.cf-emailsecurity.net | 1096 |
| 10 | mxb.global.inbound.cf-emailsecurity.net | 1096 |
info
Multiple MX hosts share a preference; delivery load-balances across them.
02Mail providerA
info
No known provider matched; self-hosted or unknown.
provider
03SPFA
pass
SPF record present.
record v=spf1 ip4:199.15.212.0/22 ip4:173.245.48.0/20 include:_spf.google.com include:spf1.mcsv.net include:spf.mandrillapp.com include:mail.zendesk.com include:stspg-customer.com include:_spf.salesforce.com -all
pass
SPF uses 7 of the 10 permitted DNS lookups.
lookups 7
pass
-all default policy.
04DKIMA
05DMARCA
pass
DMARC record present.
record v=DMARC1; p=reject; sp=reject; adkim=r; aspf=r; pct=100; rua=mailto:a1c47f179bc04efd8ee4dcd4d85dfc65@dmarc-reports.cloudflare.net,mailto:rua@cloudflare.com
pass
Enforcing policy p=reject.
warn
pct=100 is deprecated in DMARCbis; apply the policy to all mail.
06DNS healthC
warn
MX host mxa.global.inbound.cf-emailsecurity.net (141.101.90.40) has no PTR record; many receivers reject senders without reverse DNS.
host mxa.global.inbound.cf-emailsecurity.net
ip 141.101.90.40
warn
MX host mxb.global.inbound.cf-emailsecurity.net (141.101.90.40) has no PTR record; many receivers reject senders without reverse DNS.
host mxb.global.inbound.cf-emailsecurity.net
ip 141.101.90.40
warn
MX host mxb-canary.global.inbound.cf-emailsecurity.net (172.65.65.66) has no PTR record; many receivers reject senders without reverse DNS.
host mxb-canary.global.inbound.cf-emailsecurity.net
ip 172.65.65.66
warn
MX host mxa-canary.global.inbound.cf-emailsecurity.net (172.65.65.66) has no PTR record; many receivers reject senders without reverse DNS.
host mxa-canary.global.inbound.cf-emailsecurity.net
ip 172.65.65.66
pass
5 nameservers published.
count 5
pass
SOA timers are sane.
mname ns3.cloudflare.com.
rname dns.cloudflare.com.
refresh 10000
retry 2400
expire 604800
minimum 300
pass
Zone is DNSSEC-signed and validating.
07BlacklistsA
pass
172.65.65.66 is not listed on SpamCop.
target 172.65.65.66
list SpamCop
pass
141.101.90.40 is not listed on SpamCop.
target 141.101.90.40
list SpamCop
pass
172.65.65.66 is not listed on Spamhaus ZEN.
target 172.65.65.66
list Spamhaus ZEN
pass
141.101.90.40 is not listed on Spamhaus ZEN.
target 141.101.90.40
list Spamhaus ZEN
pass
172.65.65.66 is not listed on PSBL.
target 172.65.65.66
list PSBL
pass
cloudflare.com is not listed on Spamhaus DBL.
target cloudflare.com
list Spamhaus DBL
pass
cloudflare.com is not listed on Spamhaus ZRD.
target cloudflare.com
list Spamhaus ZRD
pass
141.101.90.40 is not listed on GBUdb Truncate.
target 141.101.90.40
list GBUdb Truncate
pass
172.65.65.66 is not listed on Spamhaus AuthBL.
target 172.65.65.66
list Spamhaus AuthBL
pass
172.65.65.66 is not listed on GBUdb Truncate.
target 172.65.65.66
list GBUdb Truncate
pass
141.101.90.40 is not listed on PSBL.
target 141.101.90.40
list PSBL
pass
141.101.90.40 is not listed on Spamhaus AuthBL.
target 141.101.90.40
list Spamhaus AuthBL
08Bulk sending readinessA
pass
SPF, DKIM and DMARC are all present: the domain meets the Gmail/Yahoo and Microsoft bulk-sender authentication requirements (5,000+ messages/day).
spf true
dkim true
dmarc true
threshold 5,000 messages/day
info
One-click List-Unsubscribe is a message-level header; verify it by sending a test message.
09TLSA
pass
DANE/TLSA published and DNSSEC-signed for mxb.global.inbound.cf-emailsecurity.net.
host mxb.global.inbound.cf-emailsecurity.net
usage
selector 35
matchingType 3
profileNote usage NaN is neither DANE-EE (3) nor DANE-TA (2); selector 35 is not SPKI (1); matching type 3 is not SHA-256 (1)
certMatch certificate-to-TLSA matching is verified by the SMTP probe against the live server certificate
pass
DANE/TLSA published and DNSSEC-signed for mxa.global.inbound.cf-emailsecurity.net.
host mxa.global.inbound.cf-emailsecurity.net
usage
selector 35
matchingType 3
profileNote usage NaN is neither DANE-EE (3) nor DANE-TA (2); selector 35 is not SPKI (1); matching type 3 is not SHA-256 (1)
certMatch certificate-to-TLSA matching is verified by the SMTP probe against the live server certificate
pass
DANE/TLSA published and DNSSEC-signed for mxa-canary.global.inbound.cf-emailsecurity.net.
host mxa-canary.global.inbound.cf-emailsecurity.net
usage
selector 35
matchingType 3
profileNote usage NaN is neither DANE-EE (3) nor DANE-TA (2); selector 35 is not SPKI (1); matching type 3 is not SHA-256 (1)
certMatch certificate-to-TLSA matching is verified by the SMTP probe against the live server certificate
pass
DANE/TLSA published and DNSSEC-signed for mxb-canary.global.inbound.cf-emailsecurity.net.
host mxb-canary.global.inbound.cf-emailsecurity.net
usage
selector 35
matchingType 3
profileNote usage NaN is neither DANE-EE (3) nor DANE-TA (2); selector 35 is not SPKI (1); matching type 3 is not SHA-256 (1)
certMatch certificate-to-TLSA matching is verified by the SMTP probe against the live server certificate
pass
Negotiated TLSv1.3.
tls_version TLSv1.3
host mxa-canary.global.inbound.cf-emailsecurity.net
pass
Certificate valid for 33 more day(s).
not_after 2026-08-11T23:59:59+00:00
host mxa-canary.global.inbound.cf-emailsecurity.net
pass
Certificate covers mxa-canary.global.inbound.cf-emailsecurity.net.
names mxa.us.inbound.cf-emailsecurity.net, mxb.us.inbound.cf-emailsecurity.net, mxa.global.inbound.cf-emailsecurity.net, mxb.global.inbound.cf-emailsecurity.net, mailstream-east.mxrecord.io, mailstream-west.mxrecord.io, mailstream-central.mxrecord.mx, mailstream-canary.mxrecord.io, mxa-canary.global.inbound.cf-emailsecurity.net, mxb-canary.global.inbound.cf-emailsecurity.net
host mxa-canary.global.inbound.cf-emailsecurity.net
pass
Server presented a 2-certificate chain.
chain_len 2
host mxa-canary.global.inbound.cf-emailsecurity.net
10MTA-STSA
11BIMIA
pass
BIMI record present.
BIMI draft
pass
BIMI logo (l=) is published over https.
BIMI draft
logo https://www.cloudflare.com/cloudflare_1171114652.svg
svgConfirmed true
info
Verified Mark Certificate published (Gmail requires a VMC or CMC to show the logo).
BIMI draft
vmc https://www.cloudflare.com/cloudflare_1171114652.pem
SMTP (live probe)
pass
DANE/TLSA published and DNSSEC-signed for mxb.global.inbound.cf-emailsecurity.net.
host mxb.global.inbound.cf-emailsecurity.net
usage
selector 35
matchingType 3
profileNote usage NaN is neither DANE-EE (3) nor DANE-TA (2); selector 35 is not SPKI (1); matching type 3 is not SHA-256 (1)
certMatch certificate-to-TLSA matching is verified by the SMTP probe against the live server certificate
pass
DANE/TLSA published and DNSSEC-signed for mxa.global.inbound.cf-emailsecurity.net.
host mxa.global.inbound.cf-emailsecurity.net
usage
selector 35
matchingType 3
profileNote usage NaN is neither DANE-EE (3) nor DANE-TA (2); selector 35 is not SPKI (1); matching type 3 is not SHA-256 (1)
certMatch certificate-to-TLSA matching is verified by the SMTP probe against the live server certificate
pass
DANE/TLSA published and DNSSEC-signed for mxa-canary.global.inbound.cf-emailsecurity.net.
host mxa-canary.global.inbound.cf-emailsecurity.net
usage
selector 35
matchingType 3
profileNote usage NaN is neither DANE-EE (3) nor DANE-TA (2); selector 35 is not SPKI (1); matching type 3 is not SHA-256 (1)
certMatch certificate-to-TLSA matching is verified by the SMTP probe against the live server certificate
pass
DANE/TLSA published and DNSSEC-signed for mxb-canary.global.inbound.cf-emailsecurity.net.
host mxb-canary.global.inbound.cf-emailsecurity.net
usage
selector 35
matchingType 3
profileNote usage NaN is neither DANE-EE (3) nor DANE-TA (2); selector 35 is not SPKI (1); matching type 3 is not SHA-256 (1)
certMatch certificate-to-TLSA matching is verified by the SMTP probe against the live server certificate
pass
4 of 4 MX host(s) reachable on port 25.
reachable mxa-canary.global.inbound.cf-emailsecurity.net, mxb-canary.global.inbound.cf-emailsecurity.net, mxa.global.inbound.cf-emailsecurity.net, mxb.global.inbound.cf-emailsecurity.net
unreachable (none)
pass
Greeting is 220 with a hostname (mxa-canary.us.inbound.cf-emailsecurity.net).
banner 220 mxa-canary.us.inbound.cf-emailsecurity.net ESMTP Postfix
info
Could not compare banner hostname to reverse DNS.
banner_fqdn mxa-canary.us.inbound.cf-emailsecurity.net
ptr
pass
EHLO accepted with 7 extension(s).
extensions 8BITMIME, CHUNKING, ENHANCEDSTATUSCODES, ETRN, PIPELINING, SIZE, SMTPUTF8
pass
Server advertises SMTPUTF8, so it accepts internationalized (EAI) email addresses.
pass
STARTTLS is advertised in EHLO.
pass
STARTTLS negotiated a working TLS session.
tls_version TLSv1.3
pass
Negotiated TLSv1.3.
tls_version TLSv1.3
host mxa-canary.global.inbound.cf-emailsecurity.net
pass
Certificate valid for 33 more day(s).
not_after 2026-08-11T23:59:59+00:00
host mxa-canary.global.inbound.cf-emailsecurity.net
pass
Certificate covers mxa-canary.global.inbound.cf-emailsecurity.net.
names mxa.us.inbound.cf-emailsecurity.net, mxb.us.inbound.cf-emailsecurity.net, mxa.global.inbound.cf-emailsecurity.net, mxb.global.inbound.cf-emailsecurity.net, mailstream-east.mxrecord.io, mailstream-west.mxrecord.io, mailstream-central.mxrecord.mx, mailstream-canary.mxrecord.io, mxa-canary.global.inbound.cf-emailsecurity.net, mxb-canary.global.inbound.cf-emailsecurity.net
host mxa-canary.global.inbound.cf-emailsecurity.net
pass
Server presented a 2-certificate chain.
chain_len 2
host mxa-canary.global.inbound.cf-emailsecurity.net
pass
Server refused external relay, as expected.
reply 554 5.7.1 <relay-test@example.com>: Relay access denied
pass
Server accepts the null sender (MAIL FROM:<>), so bounces and DSNs can be delivered.
reply 250 2.1.0 Ok
About this report
This report grades the email and DNS setup of cloudflare.com against the relevant RFCs. Each check links to the standard behind the rule. A high grade means the common causes of spoofing and poor deliverability are covered. A grade is not a guarantee that every message reaches the inbox.
Frequently asked questions
What does the grade mean?
The grade summarizes how completely the domain implements the core email authentication and DNS standards. A and B mean the main protections (SPF, DKIM, DMARC, valid MX) are in place. Lower grades flag gaps that make spoofing easier or hurt deliverability. A missing MX record caps the grade at F, a weak SPF all-qualifier caps at D, and no DMARC caps at C.
How fresh is this report?
A report is a snapshot from when it was last scanned, kept as a shareable link. If you are fixing your setup, use the Re-scan button to run every check live again.
Why is the SMTP section still loading?
The live SMTP probe connects to the mail servers from a dedicated prober, which takes a few seconds and runs separately from the DNS checks. The results stream in when ready. If SMTP was not requested for this report, that section stays empty.
I own this domain and want to stop scan.mx checking it.
Domain owners can block scanning by publishing a DNS TXT record; see the opt-out page.