C
Scanned 14 days ago. Re-scan for a fresh result after a fix.
Issues to fix
- failNo DMARC record: receivers have no policy for handling unauthenticated mail.→
- warnPartial bulk-sender setup, missing DMARC. Gmail/Yahoo and Microsoft require all three for 5,000+ messages/day.→
- warnSOA has misconfigured values: expire 259200s is too short (should exceed refresh and be >= 604800s).→
- warnNo TLS-RPT reporting address. TLS delivery failures go unreported.→
Results
01Mail exchangers (MX)A
pass
1 MX record(s) found.
records
| preference | exchange | ttl |
|---|---|---|
| 1 | smtp.google.com | 3600 |
info
Only one MX host, a secondary MX adds delivery resilience.
02Mail providerA
info
Mail provider: Google Workspace.
provider google
03SPFA
pass
SPF record present.
record v=spf1 include:_spf.google.com ~all
pass
SPF uses 1 of the 10 permitted DNS lookups.
lookups 1
pass
~all default policy.
04DKIMA
pass
Selector google key is ~2048-bit.
selector google
record v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w…IDAQAB
bits 2048
05DMARCC
fail
No DMARC record: receivers have no policy for handling unauthenticated mail.
06DNS healthA
pass
4 nameservers published.
count 4
warn
SOA has misconfigured values: expire 259200s is too short (should exceed refresh and be >= 604800s).
mname nsd1.squarespacedns.com.
rname cloud-dns-hostmaster.google.com.
refresh 21600
retry 3600
expire 259200
minimum 300
issues expire 259200s is too short (should exceed refresh and be >= 604800s)
pass
Zone is DNSSEC-signed and validating.
07BlacklistsA
info
IPv6 MX addresses are not checked against IP DNSBLs.
pass
172.253.132.26 is not listed on GBUdb Truncate.
target 172.253.132.26
list GBUdb Truncate
pass
172.253.132.27 is not listed on Spamhaus ZEN.
target 172.253.132.27
list Spamhaus ZEN
pass
172.253.132.26 is not listed on PSBL.
target 172.253.132.26
list PSBL
pass
172.253.132.27 is not listed on SpamCop.
target 172.253.132.27
list SpamCop
pass
172.253.132.26 is not listed on Spamhaus ZEN.
target 172.253.132.26
list Spamhaus ZEN
pass
172.253.132.26 is not listed on SpamCop.
target 172.253.132.26
list SpamCop
pass
sidra-studio.com is not listed on Spamhaus ZRD.
target sidra-studio.com
list Spamhaus ZRD
pass
172.253.132.27 is not listed on PSBL.
target 172.253.132.27
list PSBL
pass
172.253.132.26 is not listed on Spamhaus AuthBL.
target 172.253.132.26
list Spamhaus AuthBL
pass
172.253.132.27 is not listed on GBUdb Truncate.
target 172.253.132.27
list GBUdb Truncate
pass
172.253.132.27 is not listed on Spamhaus AuthBL.
target 172.253.132.27
list Spamhaus AuthBL
pass
sidra-studio.com is not listed on Spamhaus DBL.
target sidra-studio.com
list Spamhaus DBL
08Bulk sending readinessA
warn
Partial bulk-sender setup, missing DMARC. Gmail/Yahoo and Microsoft require all three for 5,000+ messages/day.
spf true
dkim true
dmarc false
threshold 5,000 messages/day
info
One-click List-Unsubscribe is a message-level header. Verify by sending a test message.
09TLSA
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts smtp.google.com
10MTA-STSA
11BIMIA
info
No BIMI record. No brand logo is published for inboxes with BIMI support.
BIMI draft
About this report
This report grades the email and DNS setup of sidra-studio.com against the relevant RFCs. Each check links to the standard behind the rule. A high grade means the common causes of spoofing and poor deliverability are covered. A grade is not a guarantee that every message reaches the inbox.
Frequently asked questions
What does the grade mean?
The grade summarizes how completely the domain implements the core email authentication and DNS standards. A and B mean the main protections (SPF, DKIM, DMARC, valid MX) are in place. Lower grades flag gaps that make spoofing easier or hurt deliverability. A missing MX record caps the grade at F, a weak SPF all-qualifier caps at D, and no DMARC caps at C.
How fresh is this report?
A report is a snapshot from when it was last scanned, kept as a shareable link. If you are fixing your setup, use the Re-scan button to run every check live again.
Why is the SMTP section still loading?
The live SMTP probe connects to the mail servers from a dedicated prober, which takes a few seconds and runs separately from the DNS checks. The results stream in when ready. If SMTP was not requested for this report, that section stays empty.
I own this domain and want to stop scan.mx checking it.
Domain owners can block scanning by publishing a DNS TXT record; see the opt-out page.