C
lemonleadership.de
Score 78/100 · 1 failing, 2 warnings
Mail provider: lima-city.de

Scanned 4 hours ago. Re-scan for a fresh result after a fix.

Results

01Mail exchangers (MX)A
pass
1 MX record(s) found.
records
preferenceexchangettl
0mail.lima-city.de1800
info
Only one MX host, a secondary MX adds delivery resilience.
02Mail providerA
info
Mail is handled by lima-city.de, a self-hosted or independent provider.
provider lima-city.de
03SPFC
fail
No SPF record: receivers cannot verify which hosts may send mail for this domain.
04DKIMA
info
No DKIM selector found via common probes (a _domainkey subtree exists but no common selector matched), the domain may use a custom selector.
05DMARCA
pass
DMARC record present.
record v=DMARC1; p=quarantine
pass
Enforcing policy p=quarantine.
p quarantine
rua false
06DNS healthA
pass
3 nameservers published.
count 3
pass
SOA timers are sane.
mname ns1.lima-city.de.
rname hostmaster.lima-city.de.
refresh 86400
retry 7200
expire 1209600
minimum 3600
pass
Zone is DNSSEC-signed and validating.
07BlacklistsA
info
IPv6 MX addresses are not checked against IP DNSBLs.
pass
212.83.45.134 is not listed on Spamhaus ZEN.
target 212.83.45.134
list Spamhaus ZEN
pass
212.83.45.134 is not listed on Spamhaus AuthBL.
target 212.83.45.134
list Spamhaus AuthBL
pass
212.83.45.134 is not listed on SpamCop.
target 212.83.45.134
list SpamCop
pass
212.83.45.134 is not listed on GBUdb Truncate.
target 212.83.45.134
list GBUdb Truncate
pass
212.83.45.134 is not listed on PSBL.
target 212.83.45.134
list PSBL
pass
lemonleadership.de is not listed on Spamhaus ZRD.
target lemonleadership.de
list Spamhaus ZRD
pass
lemonleadership.de is not listed on Spamhaus DBL.
target lemonleadership.de
list Spamhaus DBL
08Bulk sending readinessA
warn
Partial bulk-sender setup, missing SPF, DKIM. Gmail/Yahoo and Microsoft require all three for 5,000+ messages/day.
spf false
dkim false
dmarc true
threshold 5,000 messages/day
info
One-click List-Unsubscribe is a message-level header. Verify by sending a test message.
09TLSA
pass
DANE/TLSA published and DNSSEC-signed for mail.lima-city.de.
host mail.lima-city.de
usage 2
selector 1
matchingType 1
profileNote selector 1 is unusual for usage 2 (expected 0)
certMatch certificate-to-TLSA matching is verified by the SMTP probe against the live server certificate
pass
Negotiated TLSv1.3.
tls_version TLSv1.3
host mail.lima-city.de
pass
Certificate valid for 86 more day(s).
not_after 2026-11-30T02:24:48+00:00
host mail.lima-city.de
pass
Certificate covers mail.lima-city.de.
names mail.lima-city.de, ssl-secured.email
host mail.lima-city.de
pass
Server presented a 3-certificate chain.
chain_len 3
host mail.lima-city.de
10MTA-STSA
info
No MTA-STS policy. Inbound mail is delivered without enforced TLS.
warn
No TLS-RPT reporting address. TLS delivery failures go unreported.
11BIMIA
info
No BIMI record. No brand logo is published for inboxes with BIMI support.
BIMI draft
SMTP (live probe)
pass
DANE/TLSA published and DNSSEC-signed for mail.lima-city.de.
host mail.lima-city.de
usage 2
selector 1
matchingType 1
profileNote selector 1 is unusual for usage 2 (expected 0)
certMatch certificate-to-TLSA matching is verified by the SMTP probe against the live server certificate
pass
1 of 1 MX host(s) reachable on port 25.
reachable mail.lima-city.de
unreachable (none)
pass
Greeting is 220 with a hostname (mail.lima-city.de).
banner 220 mail.lima-city.de ESMTP Postfix (Debian/GNU)
pass
Banner hostname matches reverse DNS.
banner_fqdn mail.lima-city.de
ptr mail.lima-city.de
pass
EHLO accepted with 8 extension(s).
extensions 8BITMIME, AUTH, AUTH=PLAIN, DSN, ENHANCEDSTATUSCODES, ETRN, PIPELINING, SIZE
info
Server does not advertise SMTPUTF8; internationalized (EAI) addresses may be rejected.
info
Server does not advertise REQUIRETLS; senders cannot demand TLS-only delivery to this host.
pass
STARTTLS is advertised in EHLO.
pass
STARTTLS negotiated a working TLS session.
tls_version TLSv1.3
pass
Negotiated TLSv1.3.
tls_version TLSv1.3
host mail.lima-city.de
pass
Certificate valid for 86 more day(s).
not_after 2026-11-30T02:24:48+00:00
host mail.lima-city.de
pass
Certificate covers mail.lima-city.de.
names mail.lima-city.de, ssl-secured.email
host mail.lima-city.de
pass
Server presented a 3-certificate chain.
chain_len 3
host mail.lima-city.de
pass
Server refused external relay, as expected.
reply 556 5.1.10 <relay-test@example.com>: Recipient address rejected: Domain example.com does not accept mail (nullMX)
pass
Server accepts the null sender (MAIL FROM:<>), so bounces and DSNs can be delivered.
reply 250 2.1.0 Ok

About this report

This report grades the email and DNS setup of lemonleadership.de against the relevant RFCs. Each check links to the standard behind the rule. A high grade means the common causes of spoofing and poor deliverability are covered. A grade is not a guarantee that every message reaches the inbox.

Frequently asked questions

What does the grade mean?
The grade summarizes how completely the domain implements the core email authentication and DNS standards. A and B mean the main protections (SPF, DKIM, DMARC, valid MX) are in place. Lower grades flag gaps that make spoofing easier or hurt deliverability. A missing MX record caps the grade at F, a weak SPF all-qualifier caps at D, and no DMARC caps at C.
How fresh is this report?
A report is a snapshot from when it was last scanned, kept as a shareable link. If you are fixing your setup, use the Re-scan button to run every check live again.
Why is the SMTP section still loading?
The live SMTP probe connects to the mail servers from a dedicated prober, which takes a few seconds and runs separately from the DNS checks. The results stream in when ready. If SMTP was not requested for this report, that section stays empty.
I own this domain and want to stop scan.mx checking it.
Domain owners can block scanning by publishing a DNS TXT record; see the opt-out page.