MailAuthWatch
A95/100

digicert.com

Solid. A couple of things could still be tighter. 1 item below, ordered by how much inbox it is costing you.

SPF PASSDKIM 1024-BITDMARC QUARANTINEMX OK
Monitor this domainRe-run checkMeasured 0s ago · 83 ms · public DNS

Fix these, in this order

ranked by impact
1
3 DKIM keys are 1024-bit.

Selectors selector2._domainkey, mail._domainkey, m1._domainkey are under 2048 bits, which some receivers already downgrade.

Do this: rotate to a 2048-bit key at the sending service.

Records found

SPF · TXT
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:mktomail.com include:em2881.digicert.com ~all
DMARC · _dmarc.digicert.com
v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email,mailto:dmarc@digicert.com
DKIM · 8 of 79 selectors
selector1._domainkey · 2048-bit
selector2._domainkey · 1024-bit
s1._domainkey · 2048-bit
s2._domainkey · 2048-bit
mail._domainkey · 1024-bit
zendesk1._domainkey · 2048-bit
zendesk2._domainkey · 2048-bit
m1._domainkey · 1024-bit
MX · Microsoft 365
0 digicert-com.mail.protection.outlook.com

Grade history

Free checks keep nothing. Monitoring records every daily measurement and alerts you on change.
History goes back as far as your subscription.

SPF OK

v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:mktomail.com include:em2881.digicert.com ~all
DNS lookups
3 of 10 allowed
Final mechanism
~all
  • Noteinclude:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email uses per-message macros and is evaluated by the receiver for each message. It costs one lookup here; its own lookups depend on the sender.

Include tree

3 / 10
digicert.com0
├─ include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email (macro, evaluated per message)+1
├─ include:mktomail.com+1
└─ include:em2881.digicert.com+1

DKIM OK

DKIM selectors cannot be listed from DNS, so 79 selectors used by common providers were probed.

SelectorKeyRecord
selector1RSA 2048-bit OKv=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA19Qf9Q7UuSdftbRilKtLadhvip33…
selector2RSA 1024-bit Weakv=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDI+V0DRBo1bjBrishqApiPhZ5ftqXd1i4x…
s1RSA 2048-bit OKk=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA10onRtcr4fuQkEGZIv4Z4PtVzt6YMERq…
s2RSA 2048-bit OKk=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyMqoajmV2q5kI7/WoBoEo+Q1zCq8CFrt…
mailRSA 1024-bit Weakv=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQvzF59ybcyNc79Fh6Vt2xv7M6GmCe7S2FLdfOKdv…
zendesk1RSA 2048-bit OKv=DKIM1;t=s;n=core;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9IqdLrO3Zr2/56MHt8o…
zendesk2RSA 2048-bit OKv=DKIM1; t=s; n=core; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmiSFNkgXrO3I8aO…
m1RSA 1024-bit Weakk=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDFUlNZvtGDlIGDRtzyRQydM9yRInD5YMx86QpgZ3v7p…
  • WarningDKIM selectors "selector2", "mail", "m1" use 1024-bit keys. Rotate to 2048 bits.

DMARC OK

v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email,mailto:dmarc@digicert.com
Policy
p=quarantine
Applies to
100% of failing mail
Aggregate reports
mailto:dmarc_agg@vali.email mailto:dmarc@digicert.com
  • NotePolicy is p=quarantine. p=reject is the strongest protection once you are confident all senders are aligned.

Mail exchange and extras

  • OK No problems detected.
MTA-STS
Not published optional: enforces TLS for inbound mail
TLS-RPT
Not published
BIMI
OK v=BIMI1; l=https://vmc.digicert.com/721f074c-2137-4e32-b428-6028b7c9a028.svg; a=https://vmc.digicert.com/721f074c-2137-4e32-b428-6028b7c9a028.pem

How the grade is calculated

Score 95/100. SPF present and valid. SPF ends with ~all. DKIM found (8 selectors). DKIM key is 2048-bit or stronger. DMARC present and valid. DMARC policy is quarantine. DMARC aggregate reporting enabled. SPF contributes up to 35 points, DKIM up to 25, DMARC up to 40 (policy strength and reporting). Any critical issue caps the grade at C. Lookups that failed are shown as "not measured" and never counted as missing.

Check another domain: