claude.ai
Email authentication is in good shape.
Nothing to fix
ranked by impactSPF present and valid. SPF ends with -all. Domain declares it sends no mail (SPF -all, no MX), so DKIM is not applicable. DMARC present and valid. DMARC policy is reject. DMARC aggregate reporting enabled. The only thing left is to make sure it stays that way.
Records found
Grade history
SPF OK
v=spf1 -all
- DNS lookups
- 0 of 10 allowed
- Final mechanism
-all
- OK No problems detected.
DKIM Not found
DKIM selectors cannot be listed from DNS, so 79 selectors used by common providers were probed. "Not found" means none of those selectors exist; the domain may still sign with a custom selector.
- NoteThis zone answers every _domainkey name (wildcard DNS), so only selectors whose record differs from the wildcard and contains a public key are counted.
DMARC OK
v=DMARC1; p=reject; rua=mailto:77e00ffe8c9a4e58815efcec52c89399@dmarc-reports.cloudflare.net; fo=1
- Policy
p=reject- Applies to
- 100% of failing mail
- Aggregate reports
mailto:77e00ffe8c9a4e58815efcec52c89399@dmarc-reports.cloudflare.net
- OK No problems detected.
Mail exchange and extras
- NoteNo MX records: this domain does not receive mail. If it also never sends mail, publish "v=spf1 -all" and a p=reject DMARC record to stop spoofing.
- MTA-STS
- Not published optional: enforces TLS for inbound mail
- TLS-RPT
- Not published
- BIMI
- Not published optional: brand logo in inboxes, requires p=quarantine or reject
How the grade is calculated
Score 100/100. SPF present and valid. SPF ends with -all. Domain declares it sends no mail (SPF -all, no MX), so DKIM is not applicable. DMARC present and valid. DMARC policy is reject. DMARC aggregate reporting enabled. SPF contributes up to 35 points, DKIM up to 25, DMARC up to 40 (policy strength and reporting). Any critical issue caps the grade at C. Lookups that failed are shown as "not measured" and never counted as missing.
Check another domain:
Other recently graded domains
Public checks from the last few days. Every report is re-measured from DNS when opened.