ebay.com
Solid. A couple of things could still be tighter. 2 items below, ordered by how much inbox they are costing you.
Fix these, in this order
ranked by impactSelectors google._domainkey, k1._domainkey, s2._domainkey, dkim._domainkey, mandrill._domainkey, m1._domainkey, smtpapi._domainkey, dk._domainkey are under 2048 bits, which some receivers already downgrade.
Do this: rotate to a 2048-bit key at the sending service.
Nothing is failing yet. This is the warning you want before it does.
Do this: trim an unused include now, or monitor so the next addition is caught the same day.
Records found
k1._domainkey · 1024-bit
s1._domainkey · 2048-bit
s2._domainkey · 1024-bit
dkim._domainkey · 1024-bit
mandrill._domainkey · 1024-bit
mte1._domainkey · 2048-bit
mte2._domainkey · 2048-bit
m1._domainkey · 1024-bit
smtpapi._domainkey · 1024-bit
dk._domainkey · 1024-bit
10 mx2.hc2186-24.iphmx.com
Grade history
SPF OK
v=spf1 include:c._spf.ebay.com include:p._spf.ebay.com include:p2._spf.ebay.com ~all
- DNS lookups
- 10 of 10 allowed
- Final mechanism
~all
- WarningSPF uses 10 of 10 allowed DNS lookups. Adding one more service may break SPF.
Include tree
10 / 10DKIM OK
DKIM selectors cannot be listed from DNS, so 79 selectors used by common providers were probed.
| Selector | Key | Record |
|---|---|---|
google | RSA 1024-bit Weak | v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCJwXEYLE7cQGgp2JLji5rlXn+Gvg82N5Xm… |
k1 | RSA 1024-bit Weak | k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i8… |
s1 | RSA 2048-bit OK | k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvdHM1b9gL7bs31ddN9tu3tcsx7VLLANF… |
s2 | RSA 1024-bit Weak | k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtOlWTxAj1yyBDwjoY2Jptoct/r3p04UZB5Ovr… |
dkim | RSA 1024-bit Weak | v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDLM0fpK/rhklYDRJSBQ6bSyZKjQxTeEnZy… |
mandrill | RSA 1024-bit Weak | v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrLHiExVd55zd/IQ/J/mRwSRMAocV/hMB3… |
mte1 | RSA 2048-bit OK | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GGE1A9cwHjf5KYMV0GdrKcEhCVg… |
mte2 | RSA 2048-bit OK | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt7NkXm8fhrVVfUvX7UQBHmn8nlT1… |
m1 | RSA 1024-bit Weak | v=DKIM1;k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCP+LGyK+dfGJqTPTBP3CzBYNOAouWBYE4LH5… |
smtpapi | RSA 1024-bit Weak | k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r… |
dk | RSA 1024-bit Weak | k=rsa; t=n; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDLM0fpK/rhklYDRJSBQ6bSyZKjQxTeEnZywzod… |
- WarningDKIM selectors "google", "k1", "s2", "dkim", "mandrill", "m1", "smtpapi", "dk" use 1024-bit keys. Rotate to 2048 bits.
DMARC OK
v=DMARC1; p=reject; rua=mailto:ebay@rua.agari.com; ruf=mailto:ebay@ruf.agari.com; fo=1; rf=afrf; pct=100
- Policy
p=reject- Applies to
- 100% of failing mail
- Aggregate reports
mailto:ebay@rua.agari.com
- OK No problems detected.
Mail exchange and extras
- OK No problems detected.
- MTA-STS
- Not published optional: enforces TLS for inbound mail
- TLS-RPT
- Not published
- BIMI
- OK
v=BIMI1;l=https://vmc.digicert.com/9e57aa28-3230-463f-b92e-ba8cd5612c17.svg;a=https://vmc.digicert.com/9e57aa28-3230-463f-b92e-ba8cd5612c17.pem
How the grade is calculated
Score 100/100. SPF present and valid. SPF ends with ~all. DKIM found (11 selectors). DKIM key is 2048-bit or stronger. DMARC present and valid. DMARC policy is reject. DMARC aggregate reporting enabled. SPF contributes up to 35 points, DKIM up to 25, DMARC up to 40 (policy strength and reporting). Any critical issue caps the grade at C. Lookups that failed are shown as "not measured" and never counted as missing.
Check another domain:
Other recently graded domains
Public checks from the last few days. Every report is re-measured from DNS when opened.