C
newconcepttravel.com
Score 76/100 · 3 failing, 5 warnings
Mail provider: newconcepttravel.com

Scanned 3 hours ago. Re-scan for a fresh result after a fix.

Results

01Mail exchangers (MX)A
pass
1 MX record(s) found.
records
preferenceexchangettl
0mail.newconcepttravel.com14400
info
Only one MX host, a secondary MX adds delivery resilience.
warn
All MX hosts resolve to a single IP, no address-level redundancy.
ip 80.86.107.237
02Mail providerA
info
Mail is handled by newconcepttravel.com, a self-hosted or independent provider.
provider newconcepttravel.com
03SPFA
pass
SPF record present.
record v=spf1 a mx ip4:80.86.107.237 ip4:151.193.224.244/31 ip4:151.193.65.92/31 ip4:151.193.220.18 ip4:151.193.220.20 include:_spf.protonmail.ch include:spf.sabre.com include:_spf.salesforce.com include:spf-0057e504.pphosted.com include:_relay.amadeus.com ~all
warn
SPF uses 10 of the 10 permitted DNS lookups, little headroom remains.
lookups 10
pass
~all default policy.
04DKIMA
pass
Selector default key is ~2048-bit.
selector default
record v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w…IDAQAB;
bits 2048
warn
Selector s2 key is ~1024-bit, rotate to 2048-bit.
selector s2
record k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQ…IDAQAB
bits 1024
pass
Selector s1 key is ~2048-bit.
selector s1
record k=rsa; t=s; p=MIIBIjANBgkqhkiG9w…IDAQAB
bits 2048
info
DKIM2 reuses these same selector._domainkey records and advertises no capability, so support cannot be detected from DNS. The 3 published key(s) carry over as they are. Adding an Ed25519 key (RFC 8463) prepares for it.
draft-ietf-dkim-dkim2-spec
keys 3
ed25519 false
05DMARCA
pass
DMARC record present.
record v=DMARC1; p=none; rua=mailto:dmarc@newconcepttravel.com;
warn
p=none: monitoring only, unauthenticated mail is not blocked.
p none
rua true
06DNS healthA
pass
2 nameservers published.
count 2
pass
SOA timers are sane.
mname ns-1.ines.ro.
rname hostmaster.ines.ro.
refresh 3600
retry 1800
expire 1209600
minimum 300
info
Zone is not DNSSEC-signed.
07BlacklistsA
pass
newconcepttravel.com is not listed on Spamhaus ZRD.
target newconcepttravel.com
list Spamhaus ZRD
pass
80.86.107.237 is not listed on Spamhaus ZEN.
target 80.86.107.237
list Spamhaus ZEN
pass
80.86.107.237 is not listed on SpamCop.
target 80.86.107.237
list SpamCop
pass
newconcepttravel.com is not listed on Spamhaus DBL.
target newconcepttravel.com
list Spamhaus DBL
pass
80.86.107.237 is not listed on Spamhaus AuthBL.
target 80.86.107.237
list Spamhaus AuthBL
pass
80.86.107.237 is not listed on GBUdb Truncate.
target 80.86.107.237
list GBUdb Truncate
pass
80.86.107.237 is not listed on PSBL.
target 80.86.107.237
list PSBL
08Bulk sending readinessA
pass
SPF, DKIM and DMARC are all present: the domain meets the Gmail/Yahoo and Microsoft bulk-sender authentication requirements (5,000+ messages/day).
spf true
dkim true
dmarc true
threshold 5,000 messages/day
info
One-click List-Unsubscribe is a message-level header. Verify by sending a test message.
09TLSA
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts mail.newconcepttravel.com
10MTA-STSA
info
No MTA-STS policy. Inbound mail is delivered without enforced TLS.
warn
No TLS-RPT reporting address. TLS delivery failures go unreported.
11BIMIA
info
No BIMI record. No brand logo is published for inboxes with BIMI support.
BIMI draft
SMTP (live probe)
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts mail.newconcepttravel.com
pass
1 of 1 MX host(s) reachable on port 25.
reachable mail.newconcepttravel.com
unreachable (none)
fail
Server did not greet with 220 (got no reply).
banner
info
Could not compare banner hostname to reverse DNS.
banner_fqdn
ptr mail.newconcepttravel.com
fail
Server did not accept EHLO or HELO.
fail
STARTTLS is not advertised; mail to this host is delivered in cleartext.
info
Open-relay test was inconclusive (server did not reach the recipient stage).
info
Null-sender test was inconclusive.

About this report

This report grades the email and DNS setup of newconcepttravel.com against the relevant RFCs. Each check links to the standard behind the rule. A high grade means the common causes of spoofing and poor deliverability are covered. A grade is not a guarantee that every message reaches the inbox.

Frequently asked questions

What does the grade mean?
The grade summarizes how completely the domain implements the core email authentication and DNS standards. A and B mean the main protections (SPF, DKIM, DMARC, valid MX) are in place. Lower grades flag gaps that make spoofing easier or hurt deliverability. A missing MX record caps the grade at F, a weak SPF all-qualifier caps at D, and no DMARC caps at C.
How fresh is this report?
A report is a snapshot from when it was last scanned, kept as a shareable link. If you are fixing your setup, use the Re-scan button to run every check live again.
Why is the SMTP section still loading?
The live SMTP probe connects to the mail servers from a dedicated prober, which takes a few seconds and runs separately from the DNS checks. The results stream in when ready. If SMTP was not requested for this report, that section stays empty.
I own this domain and want to stop scan.mx checking it.
Domain owners can block scanning by publishing a DNS TXT record; see the opt-out page.