B
Scanned 14 days ago. Re-scan for a fresh result after a fix.
Issues to fix
- warnSelector default has an empty p= tag: the key is revoked.→
- warnSelector google has an empty p= tag: the key is revoked.→
- warnSelector selector2 has an empty p= tag: the key is revoked.→
- warnSelector s1 has an empty p= tag: the key is revoked.→
- warnSelector s2 has an empty p= tag: the key is revoked.→
- warnSelector selector1 has an empty p= tag: the key is revoked.→
- warnSelector k1 has an empty p= tag: the key is revoked.→
- warnSelector k2 has an empty p= tag: the key is revoked.→
- warnSelector mail has an empty p= tag: the key is revoked.→
- warnSelector dkim has an empty p= tag: the key is revoked.→
- warnSelector smtp has an empty p= tag: the key is revoked.→
- warnSelector mandrill has an empty p= tag: the key is revoked.→
- warnSelector pm has an empty p= tag: the key is revoked.→
- warnSelector mxvault has an empty p= tag: the key is revoked.→
- warnSelector protonmail has an empty p= tag: the key is revoked.→
- warnSelector protonmail2 has an empty p= tag: the key is revoked.→
- warnSelector fm1 has an empty p= tag: the key is revoked.→
- warnSelector fm2 has an empty p= tag: the key is revoked.→
- warnSelector fm3 has an empty p= tag: the key is revoked.→
- warnSelector zoho has an empty p= tag: the key is revoked.→
- warnSelector sig1 has an empty p= tag: the key is revoked.→
- warnSelector amazonses has an empty p= tag: the key is revoked.→
- warnSelector cm has an empty p= tag: the key is revoked.→
- warnNo TLS-RPT reporting address. TLS delivery failures go unreported.→
Results
01Mail exchangers (MX)A
pass
1 MX record(s) found.
records
| preference | exchange | ttl |
|---|---|---|
| 0 | . | 300 |
info
Null MX (0 .): the domain explicitly does not accept mail.
02SPFA
pass
SPF record present.
record v=spf1 -all
pass
SPF uses 0 of the 10 permitted DNS lookups.
lookups 0
pass
-all default policy.
03DKIMF
warn
Selector default has an empty p= tag: the key is revoked.
selector default
record v=DKIM1; p=
warn
Selector google has an empty p= tag: the key is revoked.
selector google
record v=DKIM1; p=
warn
Selector selector2 has an empty p= tag: the key is revoked.
selector selector2
record v=DKIM1; p=
warn
Selector s1 has an empty p= tag: the key is revoked.
selector s1
record v=DKIM1; p=
warn
Selector s2 has an empty p= tag: the key is revoked.
selector s2
record v=DKIM1; p=
warn
Selector selector1 has an empty p= tag: the key is revoked.
selector selector1
record v=DKIM1; p=
warn
Selector k1 has an empty p= tag: the key is revoked.
selector k1
record v=DKIM1; p=
warn
Selector k2 has an empty p= tag: the key is revoked.
selector k2
record v=DKIM1; p=
warn
Selector mail has an empty p= tag: the key is revoked.
selector mail
record v=DKIM1; p=
warn
Selector dkim has an empty p= tag: the key is revoked.
selector dkim
record v=DKIM1; p=
warn
Selector smtp has an empty p= tag: the key is revoked.
selector smtp
record v=DKIM1; p=
warn
Selector mandrill has an empty p= tag: the key is revoked.
selector mandrill
record v=DKIM1; p=
warn
Selector pm has an empty p= tag: the key is revoked.
selector pm
record v=DKIM1; p=
warn
Selector mxvault has an empty p= tag: the key is revoked.
selector mxvault
record v=DKIM1; p=
warn
Selector protonmail has an empty p= tag: the key is revoked.
selector protonmail
record v=DKIM1; p=
warn
Selector protonmail2 has an empty p= tag: the key is revoked.
selector protonmail2
record v=DKIM1; p=
warn
Selector fm1 has an empty p= tag: the key is revoked.
selector fm1
record v=DKIM1; p=
warn
Selector fm2 has an empty p= tag: the key is revoked.
selector fm2
record v=DKIM1; p=
warn
Selector fm3 has an empty p= tag: the key is revoked.
selector fm3
record v=DKIM1; p=
warn
Selector zoho has an empty p= tag: the key is revoked.
selector zoho
record v=DKIM1; p=
warn
Selector sig1 has an empty p= tag: the key is revoked.
selector sig1
record v=DKIM1; p=
warn
Selector amazonses has an empty p= tag: the key is revoked.
selector amazonses
record v=DKIM1; p=
warn
Selector cm has an empty p= tag: the key is revoked.
selector cm
record v=DKIM1; p=
04DMARCA
pass
DMARC record present.
record v=DMARC1;p=reject;sp=reject;adkim=s;aspf=s
pass
Enforcing policy p=reject.
info
Strict alignment (adkim/aspf = s) is enforced.
05DNS healthA
06BlacklistsA
pass
example.com is not listed on Spamhaus ZRD.
target example.com
list Spamhaus ZRD
pass
example.com is not listed on Spamhaus DBL.
target example.com
list Spamhaus DBL
07Bulk sending readinessA
pass
SPF, DKIM and DMARC are all present: the domain meets the Gmail/Yahoo and Microsoft bulk-sender authentication requirements (5,000+ messages/day).
spf true
dkim true
dmarc true
threshold 5,000 messages/day
info
One-click List-Unsubscribe is a message-level header. Verify by sending a test message.
08MTA-STSA
09BIMIA
info
No BIMI record. No brand logo is published for inboxes with BIMI support.
BIMI draft
About this report
This report grades the email and DNS setup of example.com against the relevant RFCs. Each check links to the standard behind the rule. A high grade means the common causes of spoofing and poor deliverability are covered. A grade is not a guarantee that every message reaches the inbox.
Frequently asked questions
What does the grade mean?
The grade summarizes how completely the domain implements the core email authentication and DNS standards. A and B mean the main protections (SPF, DKIM, DMARC, valid MX) are in place. Lower grades flag gaps that make spoofing easier or hurt deliverability. A missing MX record caps the grade at F, a weak SPF all-qualifier caps at D, and no DMARC caps at C.
How fresh is this report?
A report is a snapshot from when it was last scanned, kept as a shareable link. If you are fixing your setup, use the Re-scan button to run every check live again.
Why is the SMTP section still loading?
The live SMTP probe connects to the mail servers from a dedicated prober, which takes a few seconds and runs separately from the DNS checks. The results stream in when ready. If SMTP was not requested for this report, that section stays empty.
I own this domain and want to stop scan.mx checking it.
Domain owners can block scanning by publishing a DNS TXT record; see the opt-out page.