A
oscn.net
Score 99/100 · 0 failing, 5 warnings
Mail provider: Microsoft 365

Scanned 4 days ago. Re-scan for a fresh result after a fix.

Results

01Mail exchangers (MX)A
pass
1 MX record(s) found.
records
preferenceexchangettl
5oscn-net.mail.protection.outlook.com86400
info
Only one MX host, a secondary MX adds delivery resilience.
02Mail providerA
info
Mail provider: Microsoft 365.
provider microsoft365
03SPFA
pass
SPF record present.
record v=spf1 mx include:spf.protection.outlook.com include:spf.zohomail360.com -all
pass
SPF uses 3 of the 10 permitted DNS lookups.
lookups 3
pass
-all default policy.
04DKIMA
warn
Selector selector1 key is ~1024-bit, rotate to 2048-bit.
selector selector1
record v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQ…IDAQAB; n=1024,1481452273,1497177073
bits 1024
05DMARCA
pass
DMARC record present.
record v=DMARC1; p=quarantine; rua=mailto:MISSecurity@oscn.net; ruf=mailto:MISSecurity@oscn.net; pct=100; adkim=s; aspf=s;
pass
Enforcing policy p=quarantine.
warn
pct=100 is deprecated in DMARCbis, apply the policy to all mail.
info
Strict alignment (adkim/aspf = s) is enforced.
06DNS healthA
pass
6 nameservers published.
count 6
warn
SOA has misconfigured values: minimum (negative-cache) TTL 180s is outside 300..86400s.
mname ns11.constellix.com.
rname dns.constellix.com.
refresh 43200
retry 3600
expire 1209600
minimum 180
issues minimum (negative-cache) TTL 180s is outside 300..86400s
info
Zone is not DNSSEC-signed.
07BlacklistsA
info
IPv6 MX addresses are not checked against IP DNSBLs.
pass
52.101.9.19 is not listed on GBUdb Truncate.
target 52.101.9.19
list GBUdb Truncate
pass
52.101.11.12 is not listed on GBUdb Truncate.
target 52.101.11.12
list GBUdb Truncate
pass
52.101.8.50 is not listed on GBUdb Truncate.
target 52.101.8.50
list GBUdb Truncate
pass
52.101.9.19 is not listed on SpamCop.
target 52.101.9.19
list SpamCop
pass
52.101.8.50 is not listed on SpamCop.
target 52.101.8.50
list SpamCop
pass
52.101.11.12 is not listed on SpamCop.
target 52.101.11.12
list SpamCop
pass
52.101.8.52 is not listed on SpamCop.
target 52.101.8.52
list SpamCop
pass
52.101.8.52 is not listed on GBUdb Truncate.
target 52.101.8.52
list GBUdb Truncate
pass
52.101.8.50 is not listed on Spamhaus ZEN.
target 52.101.8.50
list Spamhaus ZEN
pass
52.101.9.19 is not listed on Spamhaus AuthBL.
target 52.101.9.19
list Spamhaus AuthBL
pass
oscn.net is not listed on Spamhaus ZRD.
target oscn.net
list Spamhaus ZRD
pass
oscn.net is not listed on Spamhaus DBL.
target oscn.net
list Spamhaus DBL
pass
52.101.11.12 is not listed on Spamhaus AuthBL.
target 52.101.11.12
list Spamhaus AuthBL
pass
52.101.8.50 is not listed on Spamhaus AuthBL.
target 52.101.8.50
list Spamhaus AuthBL
pass
52.101.8.52 is not listed on Spamhaus ZEN.
target 52.101.8.52
list Spamhaus ZEN
pass
52.101.8.52 is not listed on Spamhaus AuthBL.
target 52.101.8.52
list Spamhaus AuthBL
pass
52.101.11.12 is not listed on PSBL.
target 52.101.11.12
list PSBL
pass
52.101.9.19 is not listed on PSBL.
target 52.101.9.19
list PSBL
pass
52.101.11.12 is not listed on Spamhaus ZEN.
target 52.101.11.12
list Spamhaus ZEN
pass
52.101.9.19 is not listed on Spamhaus ZEN.
target 52.101.9.19
list Spamhaus ZEN
pass
52.101.8.50 is not listed on PSBL.
target 52.101.8.50
list PSBL
pass
52.101.8.52 is not listed on PSBL.
target 52.101.8.52
list PSBL
08Bulk sending readinessA
pass
SPF, DKIM and DMARC are all present: the domain meets the Gmail/Yahoo and Microsoft bulk-sender authentication requirements (5,000+ messages/day).
spf true
dkim true
dmarc true
threshold 5,000 messages/day
info
One-click List-Unsubscribe is a message-level header. Verify by sending a test message.
09TLSA
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts oscn-net.mail.protection.outlook.com
pass
Negotiated TLSv1.3.
tls_version TLSv1.3
host oscn-net.mail.protection.outlook.com
pass
Certificate valid for 162 more day(s).
not_after 2027-01-14T23:59:59+00:00
host oscn-net.mail.protection.outlook.com
pass
Certificate covers oscn-net.mail.protection.outlook.com.
names mail.protection.outlook.com, *.mail.eo.outlook.com, *.mail.protection.outlook.com, mail.messaging.microsoft.com, outlook.com, *.olc.protection.outlook.com, *.pamx1.hotmail.com, *.mail.protection.outlook.de, *.mx.microsoft, *.k-v1.mx.microsoft, *.n-v1.mx.microsoft, *.q-v1.mx.microsoft, *.y-v1.mx.microsoft, *.d-v1.mx.microsoft, *.e-v1.mx.microsoft, *.a-v1.mx.microsoft, *.r-v1.mx.microsoft, *.w-v1.mx.microsoft, *.p-v1.mx.microsoft, *.x-v1.mx.microsoft, *.j-v1.mx.microsoft, *.s-v1.mx.microsoft, *.c-v1.mx.microsoft, *.b-v1.mx.microsoft, *.f-v1.mx.microsoft, *.i-v1.mx.microsoft, *.t-v1.mx.microsoft, *.m-v1.mx.microsoft, *.o-v1.mx.microsoft, *.g-v1.mx.microsoft, *.v-v1.mx.microsoft, *.h-v1.mx.microsoft, *.l-v1.mx.microsoft, *.u-v1.mx.microsoft
host oscn-net.mail.protection.outlook.com
pass
Server presented a 2-certificate chain.
chain_len 2
host oscn-net.mail.protection.outlook.com
10MTA-STSA
warn
No TLS-RPT reporting address. TLS delivery failures go unreported.
info
No MTA-STS policy. Inbound mail is delivered without enforced TLS.
11BIMIA
info
No BIMI record. No brand logo is published for inboxes with BIMI support.
BIMI draft
SMTP (live probe)
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts oscn-net.mail.protection.outlook.com
pass
1 of 1 MX host(s) reachable on port 25.
reachable oscn-net.mail.protection.outlook.com
unreachable (none)
pass
Greeting is 220 with a hostname (SA2PEPF00002251.mail.protection.outlook.com).
banner 220 SA2PEPF00002251.mail.protection.outlook.com Microsoft ESMTP MAIL Service ready at Wed, 5 Aug 2026 21:03:26 +0000 [08DEF306758AEC73]
warn
Banner hostname does not match reverse DNS.
banner_fqdn SA2PEPF00002251.mail.protection.outlook.com
ptr mail-sa9pr09cu00104.inbound.protection.outlook.com
pass
EHLO accepted with 8 extension(s).
extensions 8BITMIME, BINARYMIME, CHUNKING, DSN, ENHANCEDSTATUSCODES, PIPELINING, SIZE, SMTPUTF8
pass
Server advertises SMTPUTF8, so it accepts internationalized (EAI) email addresses.
pass
STARTTLS is advertised in EHLO.
pass
STARTTLS negotiated a working TLS session.
tls_version TLSv1.3
pass
Negotiated TLSv1.3.
tls_version TLSv1.3
host oscn-net.mail.protection.outlook.com
pass
Certificate valid for 162 more day(s).
not_after 2027-01-14T23:59:59+00:00
host oscn-net.mail.protection.outlook.com
pass
Certificate covers oscn-net.mail.protection.outlook.com.
names mail.protection.outlook.com, *.mail.eo.outlook.com, *.mail.protection.outlook.com, mail.messaging.microsoft.com, outlook.com, *.olc.protection.outlook.com, *.pamx1.hotmail.com, *.mail.protection.outlook.de, *.mx.microsoft, *.k-v1.mx.microsoft, *.n-v1.mx.microsoft, *.q-v1.mx.microsoft, *.y-v1.mx.microsoft, *.d-v1.mx.microsoft, *.e-v1.mx.microsoft, *.a-v1.mx.microsoft, *.r-v1.mx.microsoft, *.w-v1.mx.microsoft, *.p-v1.mx.microsoft, *.x-v1.mx.microsoft, *.j-v1.mx.microsoft, *.s-v1.mx.microsoft, *.c-v1.mx.microsoft, *.b-v1.mx.microsoft, *.f-v1.mx.microsoft, *.i-v1.mx.microsoft, *.t-v1.mx.microsoft, *.m-v1.mx.microsoft, *.o-v1.mx.microsoft, *.g-v1.mx.microsoft, *.v-v1.mx.microsoft, *.h-v1.mx.microsoft, *.l-v1.mx.microsoft, *.u-v1.mx.microsoft
host oscn-net.mail.protection.outlook.com
pass
Server presented a 2-certificate chain.
chain_len 2
host oscn-net.mail.protection.outlook.com
pass
Server refused external relay, as expected.
reply 501 5.1.5 Recipient address reserved by RFC 2606 [SA2PEPF00002251.namprd09.prod.outlook.com 2026-08-05T21:03:28.309Z 08DEF306758AEC73]
pass
Server accepts the null sender (MAIL FROM:<>), so bounces and DSNs can be delivered.
reply 250 2.1.0 Sender OK

About this report

This report grades the email and DNS setup of oscn.net against the relevant RFCs. Each check links to the standard behind the rule. A high grade means the common causes of spoofing and poor deliverability are covered. A grade is not a guarantee that every message reaches the inbox.

Frequently asked questions

What does the grade mean?
The grade summarizes how completely the domain implements the core email authentication and DNS standards. A and B mean the main protections (SPF, DKIM, DMARC, valid MX) are in place. Lower grades flag gaps that make spoofing easier or hurt deliverability. A missing MX record caps the grade at F, a weak SPF all-qualifier caps at D, and no DMARC caps at C.
How fresh is this report?
A report is a snapshot from when it was last scanned, kept as a shareable link. If you are fixing your setup, use the Re-scan button to run every check live again.
Why is the SMTP section still loading?
The live SMTP probe connects to the mail servers from a dedicated prober, which takes a few seconds and runs separately from the DNS checks. The results stream in when ready. If SMTP was not requested for this report, that section stays empty.
I own this domain and want to stop scan.mx checking it.
Domain owners can block scanning by publishing a DNS TXT record; see the opt-out page.