mailauthwatch.com
Solid. A couple of things could still be tighter. 2 items below, ordered by how much inbox they are costing you.
Fix these, in this order
ranked by impactSelector resend._domainkey is under 2048 bits, which some receivers already downgrade.
Do this: rotate to a 2048-bit key at the sending service.
Receivers would tell you who is sending as your domain, but nobody is listening.
Do this: append rua=mailto:dmarc@mailauthwatch.com to the DMARC record.
Records found
Grade history
SPF OK
v=spf1 include:amazonses.com -all
- DNS lookups
- 1 of 10 allowed
- Final mechanism
-all
- OK No problems detected.
Include tree
1 / 10DKIM OK
DKIM selectors cannot be listed from DNS, so 79 selectors used by common providers were probed.
| Selector | Key | Record |
|---|---|---|
resend | RSA 1024-bit Weak | p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDSEfUMQb+/0ty+FZ9mPEogziooJ54ywfSyy2e9RlyxYe4GZGQe… |
- WarningDKIM selector "resend" uses a 1024-bit key. Rotate to 2048 bits.
DMARC OK
v=DMARC1; p=reject; adkim=s; aspf=r
- Policy
p=reject- Applies to
- 100% of failing mail
- Aggregate reports
- none
- Alignment
- DKIM strict, SPF relaxed
- WarningNo rua= address: you receive no aggregate reports and cannot see who is sending as your domain.
Mail exchange and extras
- NoteNo MX records: this domain does not receive mail. If it also never sends mail, publish "v=spf1 -all" and a p=reject DMARC record to stop spoofing.
- MTA-STS
- Not published optional: enforces TLS for inbound mail
- TLS-RPT
- Not published
- BIMI
- Not published optional: brand logo in inboxes, requires p=quarantine or reject
How the grade is calculated
Score 90/100. SPF present and valid. SPF ends with -all. DKIM found (1 selector). DMARC present and valid. DMARC policy is reject. SPF contributes up to 35 points, DKIM up to 25, DMARC up to 40 (policy strength and reporting). Any critical issue caps the grade at C. Lookups that failed are shown as "not measured" and never counted as missing.
Check another domain:
Other recently graded domains
Public checks from the last few days. Every report is re-measured from DNS when opened.