B
tehniss.rs
Score 88/100 · 1 failing, 4 warnings
Mail provider: tehniss.rs

Scanned 20 days ago. Re-scan for a fresh result after a fix.

Results

01Mail exchangers (MX)A
pass
1 MX record(s) found.
records
preferenceexchangettl
0tehniss.rs300
info
Only one MX host, a secondary MX adds delivery resilience.
warn
All MX hosts resolve to a single IP, no address-level redundancy.
ip 213.240.61.78
02Mail providerA
info
Mail is handled by tehniss.rs, a self-hosted or independent provider.
provider tehniss.rs
03SPFA
pass
SPF record present.
record v=spf1 +a +mx include:_spf.mail.yahoo.com include:_spf.google.com -all
pass
SPF uses 6 of the 10 permitted DNS lookups.
lookups 6
pass
-all default policy.
04DKIMA
pass
Selector default key is ~2048-bit.
selector default
record v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w…IDAQAB;
bits 2048
warn
Selector mail key is ~1024-bit, rotate to 2048-bit.
selector mail
record v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQ…QKBgQC 2LPkx4WQuSSSTh4yYPCoMqc8FZEHcZE/mpYWG9V/Dp78AHCCPPEB4d0ajZY7nSucVd5AFTuBF52ChGhEx /yfToGkaMGzBD1yB2mcgWh4mw2xaW1YJtMu+XBUN98lWfWC0zp1M9yPAmsUSAYQjETgJ12Yd+ZxQkTapm DZZjDMMhwIDAQAB
bits 1024
info
DKIM2 reuses these same selector._domainkey records and advertises no capability, so support cannot be detected from DNS. The 2 published key(s) carry over as they are. Adding an Ed25519 key (RFC 8463) prepares for it.
draft-ietf-dkim-dkim2-spec
keys 2
ed25519 false
05DMARCA
pass
DMARC record present.
record v=DMARC1; p=quarantine; adkim=s; aspf=s; rua=mailto:b21bc4cee4b34d6884a5c672ca6139e9@dmarc-reports.cloudflare.net; ri=604800
pass
Enforcing policy p=quarantine.
p quarantine
rua true
info
Strict alignment (adkim/aspf = s) is enforced.
06DNS healthA
pass
2 nameservers published.
count 2
pass
SOA timers are sane.
mname aspen.ns.cloudflare.com.
rname dns.cloudflare.com.
refresh 10000
retry 2400
expire 604800
minimum 1800
pass
Zone is DNSSEC-signed and validating.
07BlacklistsA
pass
213.240.61.78 is not listed on SpamCop.
target 213.240.61.78
list SpamCop
pass
tehniss.rs is not listed on Spamhaus ZRD.
target tehniss.rs
list Spamhaus ZRD
pass
tehniss.rs is not listed on Spamhaus DBL.
target tehniss.rs
list Spamhaus DBL
pass
213.240.61.78 is not listed on Spamhaus ZEN.
target 213.240.61.78
list Spamhaus ZEN
pass
213.240.61.78 is not listed on GBUdb Truncate.
target 213.240.61.78
list GBUdb Truncate
pass
213.240.61.78 is not listed on PSBL.
target 213.240.61.78
list PSBL
pass
213.240.61.78 is not listed on Spamhaus AuthBL.
target 213.240.61.78
list Spamhaus AuthBL
08Bulk sending readinessA
pass
SPF, DKIM and DMARC are all present: the domain meets the Gmail/Yahoo and Microsoft bulk-sender authentication requirements (5,000+ messages/day).
spf true
dkim true
dmarc true
threshold 5,000 messages/day
info
One-click List-Unsubscribe is a message-level header. Verify by sending a test message.
09TLSC
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts tehniss.rs
pass
Negotiated TLSv1.2.
tls_version TLSv1.2
host tehniss.rs
fail
Certificate expired 571 day(s) ago.
not_after 2025-02-08T23:59:59+00:00
host tehniss.rs
pass
Certificate covers tehniss.rs.
names tehniss.rs, www.tehniss.rs
host tehniss.rs
pass
Server presented a 3-certificate chain.
chain_len 3
host tehniss.rs
10MTA-STSA
info
No MTA-STS policy. Inbound mail is delivered without enforced TLS.
warn
No TLS-RPT reporting address. TLS delivery failures go unreported.
11BIMIA
pass
BIMI record present.
BIMI draft
pass
BIMI logo (l=) is published over https.
BIMI draft
logo https://tehniss.rs/Tehniss.svg
svgConfirmed false
warn
No VMC/CMC. Gmail will not display the logo without one.
BIMI draft
SMTP (live probe)
info
No DANE/TLSA records. DANE is not deployed for these mail servers.
hosts tehniss.rs
pass
1 of 1 MX host(s) reachable on port 25.
reachable tehniss.rs
unreachable (none)
pass
Greeting is 220 with a hostname (tehniss.rs).
banner 220 tehniss.rs ESMTP Postfix (Debian/GNU)
pass
Banner hostname matches reverse DNS.
banner_fqdn tehniss.rs
ptr tehniss.rs
pass
EHLO accepted with 8 extension(s).
extensions 8BITMIME, AUTH, DSN, ENHANCEDSTATUSCODES, ETRN, PIPELINING, SIZE, VRFY
info
Server does not advertise SMTPUTF8; internationalized (EAI) addresses may be rejected.
info
Server does not advertise REQUIRETLS; senders cannot demand TLS-only delivery to this host.
pass
STARTTLS is advertised in EHLO.
pass
STARTTLS negotiated a working TLS session.
tls_version TLSv1.2
pass
Negotiated TLSv1.2.
tls_version TLSv1.2
host tehniss.rs
fail
Certificate expired 571 day(s) ago.
not_after 2025-02-08T23:59:59+00:00
host tehniss.rs
pass
Certificate covers tehniss.rs.
names tehniss.rs, www.tehniss.rs
host tehniss.rs
pass
Server presented a 3-certificate chain.
chain_len 3
host tehniss.rs
pass
Server refused external relay, as expected.
reply 554 5.7.1 <relay-test@example.com>: Relay access denied
pass
Server accepts the null sender (MAIL FROM:<>), so bounces and DSNs can be delivered.
reply 250 2.1.0 Ok

About this report

This report grades the email and DNS setup of tehniss.rs against the relevant RFCs. Each check links to the standard behind the rule. A high grade means the common causes of spoofing and poor deliverability are covered. A grade is not a guarantee that every message reaches the inbox.

Frequently asked questions

What does the grade mean?
The grade summarizes how completely the domain implements the core email authentication and DNS standards. A and B mean the main protections (SPF, DKIM, DMARC, valid MX) are in place. Lower grades flag gaps that make spoofing easier or hurt deliverability. A missing MX record caps the grade at F, a weak SPF all-qualifier caps at D, and no DMARC caps at C.
How fresh is this report?
A report is a snapshot from when it was last scanned, kept as a shareable link. If you are fixing your setup, use the Re-scan button to run every check live again.
Why is the SMTP section still loading?
The live SMTP probe connects to the mail servers from a dedicated prober, which takes a few seconds and runs separately from the DNS checks. The results stream in when ready. If SMTP was not requested for this report, that section stays empty.
I own this domain and want to stop scan.mx checking it.
Domain owners can block scanning by publishing a DNS TXT record; see the opt-out page.