digicert.com
Solid. A couple of things could still be tighter. 1 item below, ordered by how much inbox it is costing you.
Fix these, in this order
ranked by impactSelectors selector2._domainkey, mail._domainkey, m1._domainkey are under 2048 bits, which some receivers already downgrade.
Do this: rotate to a 2048-bit key at the sending service.
Records found
selector2._domainkey · 1024-bit
s1._domainkey · 2048-bit
s2._domainkey · 2048-bit
mail._domainkey · 1024-bit
zendesk1._domainkey · 2048-bit
zendesk2._domainkey · 2048-bit
m1._domainkey · 1024-bit
Grade history
SPF OK
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:mktomail.com include:em2881.digicert.com ~all
- DNS lookups
- 3 of 10 allowed
- Final mechanism
~all
- Noteinclude:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email uses per-message macros and is evaluated by the receiver for each message. It costs one lookup here; its own lookups depend on the sender.
Include tree
3 / 10DKIM OK
DKIM selectors cannot be listed from DNS, so 79 selectors used by common providers were probed.
| Selector | Key | Record |
|---|---|---|
selector1 | RSA 2048-bit OK | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA19Qf9Q7UuSdftbRilKtLadhvip33… |
selector2 | RSA 1024-bit Weak | v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDI+V0DRBo1bjBrishqApiPhZ5ftqXd1i4x… |
s1 | RSA 2048-bit OK | k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA10onRtcr4fuQkEGZIv4Z4PtVzt6YMERq… |
s2 | RSA 2048-bit OK | k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyMqoajmV2q5kI7/WoBoEo+Q1zCq8CFrt… |
mail | RSA 1024-bit Weak | v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQvzF59ybcyNc79Fh6Vt2xv7M6GmCe7S2FLdfOKdv… |
zendesk1 | RSA 2048-bit OK | v=DKIM1;t=s;n=core;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9IqdLrO3Zr2/56MHt8o… |
zendesk2 | RSA 2048-bit OK | v=DKIM1; t=s; n=core; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmiSFNkgXrO3I8aO… |
m1 | RSA 1024-bit Weak | k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDFUlNZvtGDlIGDRtzyRQydM9yRInD5YMx86QpgZ3v7p… |
- WarningDKIM selectors "selector2", "mail", "m1" use 1024-bit keys. Rotate to 2048 bits.
DMARC OK
v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email,mailto:dmarc@digicert.com
- Policy
p=quarantine- Applies to
- 100% of failing mail
- Aggregate reports
mailto:dmarc_agg@vali.emailmailto:dmarc@digicert.com
- NotePolicy is p=quarantine. p=reject is the strongest protection once you are confident all senders are aligned.
Mail exchange and extras
- OK No problems detected.
- MTA-STS
- Not published optional: enforces TLS for inbound mail
- TLS-RPT
- Not published
- BIMI
- OK
v=BIMI1; l=https://vmc.digicert.com/721f074c-2137-4e32-b428-6028b7c9a028.svg; a=https://vmc.digicert.com/721f074c-2137-4e32-b428-6028b7c9a028.pem
How the grade is calculated
Score 95/100. SPF present and valid. SPF ends with ~all. DKIM found (8 selectors). DKIM key is 2048-bit or stronger. DMARC present and valid. DMARC policy is quarantine. DMARC aggregate reporting enabled. SPF contributes up to 35 points, DKIM up to 25, DMARC up to 40 (policy strength and reporting). Any critical issue caps the grade at C. Lookups that failed are shown as "not measured" and never counted as missing.
Check another domain:
Other recently graded domains
Public checks from the last few days. Every report is re-measured from DNS when opened.