C
Scanned 16 days ago. Re-scan for a fresh result after a fix.
Issues to fix
- failNo DMARC record: receivers have no policy for handling unauthenticated mail.→
- warnPartial bulk-sender setup, missing DMARC. Gmail/Yahoo and Microsoft require all three for 5,000+ messages/day.→
- warnCertificate expires in 13 day(s).→
- warnDeep include chain (nested includes are hard to audit and can push you toward the 10-lookup limit).→
- warnNo TLS-RPT reporting address. TLS delivery failures go unreported.→
- warnGreeting is 220 but announces no FQDN.→
Results
01Mail exchangers (MX)A
pass
2 MX record(s) found.
records
| preference | exchange | ttl |
|---|---|---|
| 10 | mx01.mail.icloud.com | 3600 |
| 20 | mx02.mail.icloud.com | 3600 |
02Mail providerA
info
Mail provider: iCloud Mail.
provider icloud
03SPFA
pass
SPF record present.
record v=spf1 include:icloud.com ~all
pass
SPF uses 5 of the 10 permitted DNS lookups.
lookups 5
warn
Deep include chain (nested includes are hard to audit and can push you toward the 10-lookup limit).
depth 3
pass
~all default policy.
04DKIMA
pass
Selector sig1 key is ~2048-bit.
selector sig1
record v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w…IDAQAB
bits 2048
info
DKIM2 reuses these same selector._domainkey records and advertises no capability, so support cannot be detected from DNS. The 1 published key(s) carry over as they are. Adding an Ed25519 key (RFC 8463) prepares for it.
draft-ietf-dkim-dkim2-spec
keys 1
ed25519 false
05DMARCC
fail
No DMARC record: receivers have no policy for handling unauthenticated mail.
06DNS healthA
07BlacklistsA
pass
17.42.251.62 is not listed on SpamCop.
target 17.42.251.62
list SpamCop
pass
17.57.155.25 is not listed on SpamCop.
target 17.57.155.25
list SpamCop
pass
17.57.154.33 is not listed on SpamCop.
target 17.57.154.33
list SpamCop
pass
17.57.152.5 is not listed on SpamCop.
target 17.57.152.5
list SpamCop
pass
17.56.9.31 is not listed on SpamCop.
target 17.56.9.31
list SpamCop
pass
17.57.156.30 is not listed on SpamCop.
target 17.57.156.30
list SpamCop
pass
17.42.251.62 is not listed on GBUdb Truncate.
target 17.42.251.62
list GBUdb Truncate
pass
17.57.156.30 is not listed on GBUdb Truncate.
target 17.57.156.30
list GBUdb Truncate
pass
17.57.155.25 is not listed on GBUdb Truncate.
target 17.57.155.25
list GBUdb Truncate
pass
17.57.154.33 is not listed on GBUdb Truncate.
target 17.57.154.33
list GBUdb Truncate
pass
17.56.9.31 is not listed on GBUdb Truncate.
target 17.56.9.31
list GBUdb Truncate
pass
17.57.152.5 is not listed on GBUdb Truncate.
target 17.57.152.5
list GBUdb Truncate
pass
17.42.251.62 is not listed on PSBL.
target 17.42.251.62
list PSBL
pass
17.42.251.62 is not listed on Spamhaus ZEN.
target 17.42.251.62
list Spamhaus ZEN
info
17.56.9.31 has a Spamhaus PBL policy listing (expected for hosts not meant to send mail directly). A PBL listing does not affect a receive-only mail server.
target 17.56.9.31
list Spamhaus ZEN
remediation https://check.spamhaus.org/
pass
17.57.152.5 is not listed on PSBL.
target 17.57.152.5
list PSBL
pass
17.57.152.5 is not listed on Spamhaus ZEN.
target 17.57.152.5
list Spamhaus ZEN
pass
17.57.154.33 is not listed on Spamhaus ZEN.
target 17.57.154.33
list Spamhaus ZEN
pass
17.57.155.25 is not listed on Spamhaus ZEN.
target 17.57.155.25
list Spamhaus ZEN
pass
17.57.156.30 is not listed on Spamhaus ZEN.
target 17.57.156.30
list Spamhaus ZEN
pass
hellwig-garten-hausdienst.de is not listed on Spamhaus DBL.
target hellwig-garten-hausdienst.de
list Spamhaus DBL
pass
17.42.251.62 is not listed on Spamhaus AuthBL.
target 17.42.251.62
list Spamhaus AuthBL
pass
17.56.9.31 is not listed on Spamhaus AuthBL.
target 17.56.9.31
list Spamhaus AuthBL
pass
17.57.152.5 is not listed on Spamhaus AuthBL.
target 17.57.152.5
list Spamhaus AuthBL
pass
17.57.154.33 is not listed on Spamhaus AuthBL.
target 17.57.154.33
list Spamhaus AuthBL
pass
17.57.155.25 is not listed on Spamhaus AuthBL.
target 17.57.155.25
list Spamhaus AuthBL
pass
hellwig-garten-hausdienst.de is not listed on Spamhaus ZRD.
target hellwig-garten-hausdienst.de
list Spamhaus ZRD
pass
17.57.156.30 is not listed on PSBL.
target 17.57.156.30
list PSBL
pass
17.57.156.30 is not listed on Spamhaus AuthBL.
target 17.57.156.30
list Spamhaus AuthBL
pass
17.57.154.33 is not listed on PSBL.
target 17.57.154.33
list PSBL
pass
17.56.9.31 is not listed on PSBL.
target 17.56.9.31
list PSBL
pass
17.57.155.25 is not listed on PSBL.
target 17.57.155.25
list PSBL
08Bulk sending readinessA
warn
Partial bulk-sender setup, missing DMARC. Gmail/Yahoo and Microsoft require all three for 5,000+ messages/day.
spf true
dkim true
dmarc false
threshold 5,000 messages/day
info
One-click List-Unsubscribe is a message-level header. Verify by sending a test message.
09TLSA
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts mx01.mail.icloud.com, mx02.mail.icloud.com
pass
Negotiated TLSv1.3.
tls_version TLSv1.3
host mx01.mail.icloud.com
warn
Certificate expires in 13 day(s).
not_after 2026-09-17T18:37:42+00:00
host mx01.mail.icloud.com
pass
Certificate covers mx01.mail.icloud.com.
names mx02.mail.icloud.com, mx01.mail.icloud.com, mx3.mail.icloud.com
host mx01.mail.icloud.com
pass
Server presented a 2-certificate chain.
chain_len 2
host mx01.mail.icloud.com
10MTA-STSA
11BIMIA
info
No BIMI record. No brand logo is published for inboxes with BIMI support.
BIMI draft
SMTP (live probe)
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts mx01.mail.icloud.com, mx02.mail.icloud.com
pass
2 of 2 MX host(s) reachable on port 25.
reachable mx01.mail.icloud.com, mx02.mail.icloud.com
unreachable (none)
warn
Greeting is 220 but announces no FQDN.
banner 220 iCloud iscream SMTP proxy - p00-iscream-smtp-67584cbbc7-bf4nz 3.5.0 (2632B190-ac0661d09774)
info
Could not compare banner hostname to reverse DNS.
banner_fqdn
ptr mx02.mail.icloud.com
pass
EHLO accepted with 7 extension(s).
extensions 8BITMIME, CHUNKING, DSN, ENHANCEDSTATUSCODES, ETRN, PIPELINING, SIZE
info
Server does not advertise SMTPUTF8; internationalized (EAI) addresses may be rejected.
info
Server does not advertise REQUIRETLS; senders cannot demand TLS-only delivery to this host.
pass
STARTTLS is advertised in EHLO.
pass
STARTTLS negotiated a working TLS session.
tls_version TLSv1.3
pass
Negotiated TLSv1.3.
tls_version TLSv1.3
host mx01.mail.icloud.com
warn
Certificate expires in 13 day(s).
not_after 2026-09-17T18:37:42+00:00
host mx01.mail.icloud.com
pass
Certificate covers mx01.mail.icloud.com.
names mx02.mail.icloud.com, mx01.mail.icloud.com, mx3.mail.icloud.com
host mx01.mail.icloud.com
pass
Server presented a 2-certificate chain.
chain_len 2
host mx01.mail.icloud.com
pass
Server refused external relay, as expected.
reply 550 5.1.1 <relay-test@example.com>: user does not exist
pass
Server accepts the null sender (MAIL FROM:<>), so bounces and DSNs can be delivered.
reply 250 2.1.0 Ok
About this report
This report grades the email and DNS setup of hellwig-garten-hausdienst.de against the relevant RFCs. Each check links to the standard behind the rule. A high grade means the common causes of spoofing and poor deliverability are covered. A grade is not a guarantee that every message reaches the inbox.
Frequently asked questions
What does the grade mean?
The grade summarizes how completely the domain implements the core email authentication and DNS standards. A and B mean the main protections (SPF, DKIM, DMARC, valid MX) are in place. Lower grades flag gaps that make spoofing easier or hurt deliverability. A missing MX record caps the grade at F, a weak SPF all-qualifier caps at D, and no DMARC caps at C.
How fresh is this report?
A report is a snapshot from when it was last scanned, kept as a shareable link. If you are fixing your setup, use the Re-scan button to run every check live again.
Why is the SMTP section still loading?
The live SMTP probe connects to the mail servers from a dedicated prober, which takes a few seconds and runs separately from the DNS checks. The results stream in when ready. If SMTP was not requested for this report, that section stays empty.
I own this domain and want to stop scan.mx checking it.
Domain owners can block scanning by publishing a DNS TXT record; see the opt-out page.