B
Scanned 51 minutes ago. Re-scan for a fresh result after a fix.
Issues to fix
- warnSome MX hosts do not resolve to any address.→
- warnp=none: monitoring only, unauthenticated mail is not blocked.→
- warnFCrDNS mismatch: 173.194.41.26 -> mad01s14-in-f26.1e100.net does not resolve back to the same IP.→
- warnDeep include chain (nested includes are hard to audit and can push you toward the 10-lookup limit).→
- warnNo TLS-RPT reporting address. TLS delivery failures go unreported.→
- warnBanner hostname does not match reverse DNS.→
Results
01Mail exchangers (MX)A
pass
6 MX record(s) found.
records
| preference | exchange | ttl |
|---|---|---|
| 1 | aspmx.l.google.com | 3600 |
| 5 | alt1.aspmx.l.google.com | 3600 |
| 5 | alt2.aspmx.l.google.com | 3600 |
| 10 | alt3.aspmx.l.google.com | 3600 |
| 10 | alt4.aspmx.l.google.com | 3600 |
| 15 | oib7qtn2oey5tiez7p2tn77qbpcgwutyo3af4flq7mrkwtsimtrq.mx-verification.google.com | 3600 |
info
Multiple MX hosts share a preference, delivery load-balances across them.
warn
Some MX hosts do not resolve to any address.
hosts oib7qtn2oey5tiez7p2tn77qbpcgwutyo3af4flq7mrkwtsimtrq.mx-verification.google.com
02Mail providerA
info
Mail provider: Google Workspace.
provider google
03SPFA
pass
SPF record present.
record v=spf1 include:_spf.google.com include:secureserver.net ~all
pass
SPF uses 4 of the 10 permitted DNS lookups.
lookups 4
warn
Deep include chain (nested includes are hard to audit and can push you toward the 10-lookup limit).
depth 3
pass
~all default policy.
04DKIMA
pass
Selector google key is ~2048-bit.
selector google
record v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w…IDAQAB
bits 2048
info
DKIM2 reuses these same selector._domainkey records and advertises no capability, so support cannot be detected from DNS. The 1 published key(s) carry over as they are. Adding an Ed25519 key (RFC 8463) prepares for it.
draft-ietf-dkim-dkim2-spec
keys 1
ed25519 false
05DMARCA
pass
DMARC record present.
record v=DMARC1; p=none;
warn
p=none: monitoring only, unauthenticated mail is not blocked.
p none
rua false
06DNS healthA
warn
FCrDNS mismatch: 173.194.41.26 -> mad01s14-in-f26.1e100.net does not resolve back to the same IP.
host alt1.aspmx.l.google.com
ip 173.194.41.26
ptr mad01s14-in-f26.1e100.net
forward (none)
pass
2 nameservers published.
count 2
pass
SOA timers are sane.
mname ns69.domaincontrol.com.
rname dns.jomax.net.
refresh 28800
retry 7200
expire 604800
minimum 600
info
Zone is not DNSSEC-signed.
07BlacklistsA
info
IPv6 MX addresses are not checked against IP DNSBLs.
pass
172.253.158.27 is not listed on SpamCop.
target 172.253.158.27
list SpamCop
pass
108.177.125.27 is not listed on SpamCop.
target 108.177.125.27
list SpamCop
pass
192.178.211.27 is not listed on GBUdb Truncate.
target 192.178.211.27
list GBUdb Truncate
pass
192.178.230.27 is not listed on SpamCop.
target 192.178.230.27
list SpamCop
pass
173.194.41.26 is not listed on SpamCop.
target 173.194.41.26
list SpamCop
pass
192.178.211.27 is not listed on SpamCop.
target 192.178.211.27
list SpamCop
pass
172.253.158.27 is not listed on GBUdb Truncate.
target 172.253.158.27
list GBUdb Truncate
pass
173.194.41.26 is not listed on GBUdb Truncate.
target 173.194.41.26
list GBUdb Truncate
pass
192.178.211.27 is not listed on PSBL.
target 192.178.211.27
list PSBL
pass
173.194.41.26 is not listed on PSBL.
target 173.194.41.26
list PSBL
pass
172.253.158.27 is not listed on PSBL.
target 172.253.158.27
list PSBL
pass
108.177.125.27 is not listed on PSBL.
target 108.177.125.27
list PSBL
pass
108.177.125.27 is not listed on GBUdb Truncate.
target 108.177.125.27
list GBUdb Truncate
pass
192.178.211.27 is not listed on Spamhaus ZEN.
target 192.178.211.27
list Spamhaus ZEN
pass
173.194.41.26 is not listed on Spamhaus ZEN.
target 173.194.41.26
list Spamhaus ZEN
pass
172.253.158.27 is not listed on Spamhaus ZEN.
target 172.253.158.27
list Spamhaus ZEN
pass
192.178.230.27 is not listed on GBUdb Truncate.
target 192.178.230.27
list GBUdb Truncate
pass
108.177.125.27 is not listed on Spamhaus ZEN.
target 108.177.125.27
list Spamhaus ZEN
pass
mindbridge.net is not listed on Spamhaus ZRD.
target mindbridge.net
list Spamhaus ZRD
pass
mindbridge.net is not listed on Spamhaus DBL.
target mindbridge.net
list Spamhaus DBL
pass
192.178.230.27 is not listed on Spamhaus ZEN.
target 192.178.230.27
list Spamhaus ZEN
pass
192.178.211.27 is not listed on Spamhaus AuthBL.
target 192.178.211.27
list Spamhaus AuthBL
pass
173.194.41.26 is not listed on Spamhaus AuthBL.
target 173.194.41.26
list Spamhaus AuthBL
pass
172.253.158.27 is not listed on Spamhaus AuthBL.
target 172.253.158.27
list Spamhaus AuthBL
pass
192.178.230.27 is not listed on Spamhaus AuthBL.
target 192.178.230.27
list Spamhaus AuthBL
pass
108.177.125.27 is not listed on Spamhaus AuthBL.
target 108.177.125.27
list Spamhaus AuthBL
pass
192.178.230.27 is not listed on PSBL.
target 192.178.230.27
list PSBL
08Bulk sending readinessA
pass
SPF, DKIM and DMARC are all present: the domain meets the Gmail/Yahoo and Microsoft bulk-sender authentication requirements (5,000+ messages/day).
spf true
dkim true
dmarc true
threshold 5,000 messages/day
info
One-click List-Unsubscribe is a message-level header. Verify by sending a test message.
09TLSA
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com, alt4.aspmx.l.google.com, oib7qtn2oey5tiez7p2tn77qbpcgwutyo3af4flq7mrkwtsimtrq.mx-verification.google.com
pass
Negotiated TLSv1.3.
tls_version TLSv1.3
host aspmx.l.google.com
pass
Certificate valid for 47 more day(s).
not_after 2026-11-02T08:39:01+00:00
host aspmx.l.google.com
pass
Certificate covers aspmx.l.google.com.
names mx.google.com, smtp.google.com, aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com, alt4.aspmx.l.google.com, gmail-smtp-in.l.google.com, alt1.gmail-smtp-in.l.google.com, alt2.gmail-smtp-in.l.google.com, alt3.gmail-smtp-in.l.google.com, alt4.gmail-smtp-in.l.google.com, gmr-smtp-in.l.google.com, alt1.gmr-smtp-in.l.google.com, alt2.gmr-smtp-in.l.google.com, alt3.gmr-smtp-in.l.google.com, alt4.gmr-smtp-in.l.google.com, mx1.smtp.goog, mx2.smtp.goog, mx3.smtp.goog, mx4.smtp.goog, aspmx2.googlemail.com, aspmx3.googlemail.com, aspmx4.googlemail.com, aspmx5.googlemail.com, gmr-mx.google.com
host aspmx.l.google.com
pass
Server presented a 3-certificate chain.
chain_len 3
host aspmx.l.google.com
10MTA-STSA
11BIMIA
info
No BIMI record. No brand logo is published for inboxes with BIMI support.
BIMI draft
SMTP (live probe)
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com, alt4.aspmx.l.google.com, oib7qtn2oey5tiez7p2tn77qbpcgwutyo3af4flq7mrkwtsimtrq.mx-verification.google.com
pass
5 of 5 MX host(s) reachable on port 25.
reachable aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com, alt4.aspmx.l.google.com
unreachable (none)
pass
Greeting is 220 with a hostname (mx.google.com).
banner 220 mx.google.com ESMTP 5a478bee46e88-33bf5a6d2e6si3800224eec.20 - gsmtp
warn
Banner hostname does not match reverse DNS.
banner_fqdn mx.google.com
ptr lcbomp-in-f27.1e100.net
pass
EHLO accepted with 6 extension(s).
extensions 8BITMIME, CHUNKING, ENHANCEDSTATUSCODES, PIPELINING, SIZE, SMTPUTF8
pass
Server advertises SMTPUTF8, so it accepts internationalized (EAI) email addresses.
info
Server does not advertise REQUIRETLS; senders cannot demand TLS-only delivery to this host.
pass
STARTTLS is advertised in EHLO.
pass
STARTTLS negotiated a working TLS session.
tls_version TLSv1.3
pass
Negotiated TLSv1.3.
tls_version TLSv1.3
host aspmx.l.google.com
pass
Certificate valid for 47 more day(s).
not_after 2026-11-02T08:39:01+00:00
host aspmx.l.google.com
pass
Certificate covers aspmx.l.google.com.
names mx.google.com, smtp.google.com, aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com, alt4.aspmx.l.google.com, gmail-smtp-in.l.google.com, alt1.gmail-smtp-in.l.google.com, alt2.gmail-smtp-in.l.google.com, alt3.gmail-smtp-in.l.google.com, alt4.gmail-smtp-in.l.google.com, gmr-smtp-in.l.google.com, alt1.gmr-smtp-in.l.google.com, alt2.gmr-smtp-in.l.google.com, alt3.gmr-smtp-in.l.google.com, alt4.gmr-smtp-in.l.google.com, mx1.smtp.goog, mx2.smtp.goog, mx3.smtp.goog, mx4.smtp.goog, aspmx2.googlemail.com, aspmx3.googlemail.com, aspmx4.googlemail.com, aspmx5.googlemail.com, gmr-mx.google.com
host aspmx.l.google.com
pass
Server presented a 3-certificate chain.
chain_len 3
host aspmx.l.google.com
pass
Server refused external relay, as expected.
reply 550-5.1.1 The email account that you tried to reach does not exist. Please try
pass
Server accepts the null sender (MAIL FROM:<>), so bounces and DSNs can be delivered.
reply 250 2.1.0 OK 5a478bee46e88-33bf5a6d2e6si3800224eec.20 - gsmtp
About this report
This report grades the email and DNS setup of mindbridge.net against the relevant RFCs. Each check links to the standard behind the rule. A high grade means the common causes of spoofing and poor deliverability are covered. A grade is not a guarantee that every message reaches the inbox.
Frequently asked questions
What does the grade mean?
The grade summarizes how completely the domain implements the core email authentication and DNS standards. A and B mean the main protections (SPF, DKIM, DMARC, valid MX) are in place. Lower grades flag gaps that make spoofing easier or hurt deliverability. A missing MX record caps the grade at F, a weak SPF all-qualifier caps at D, and no DMARC caps at C.
How fresh is this report?
A report is a snapshot from when it was last scanned, kept as a shareable link. If you are fixing your setup, use the Re-scan button to run every check live again.
Why is the SMTP section still loading?
The live SMTP probe connects to the mail servers from a dedicated prober, which takes a few seconds and runs separately from the DNS checks. The results stream in when ready. If SMTP was not requested for this report, that section stays empty.
I own this domain and want to stop scan.mx checking it.
Domain owners can block scanning by publishing a DNS TXT record; see the opt-out page.