MailAuthWatch
A100/100

philo.com

Solid. A couple of things could still be tighter. 1 item below, ordered by how much inbox it is costing you.

SPF PASSDKIM 1024-BITDMARC REJECTMX OK
Monitor this domainRe-run checkMeasured 0s ago · 400 ms · public DNS

Fix these, in this order

ranked by impact
1
2 DKIM keys are 1024-bit.

Selectors k1._domainkey, s2._domainkey are under 2048 bits, which some receivers already downgrade.

Do this: rotate to a 2048-bit key at the sending service.

Records found

SPF · TXT
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~all
DMARC · _dmarc.philo.com
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email
DKIM · 6 of 79 selectors
google._domainkey · 2048-bit
k1._domainkey · 1024-bit
k2._domainkey · 2048-bit
k3._domainkey · 2048-bit
s1._domainkey · 2048-bit
s2._domainkey · 1024-bit
MX · Google Workspace
1 aspmx.l.google.com
5 alt1.aspmx.l.google.com
5 alt2.aspmx.l.google.com
10 aspmx2.googlemail.com
10 aspmx3.googlemail.com

Grade history

Free checks keep nothing. Monitoring records every daily measurement and alerts you on change.
History goes back as far as your subscription.

SPF OK

v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~all
DNS lookups
1 of 10 allowed
Final mechanism
~all
  • Noteinclude:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email uses per-message macros and is evaluated by the receiver for each message. It costs one lookup here; its own lookups depend on the sender.

Include tree

1 / 10
philo.com0
└─ include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email (macro, evaluated per message)+1

DKIM OK

DKIM selectors cannot be listed from DNS, so 79 selectors used by common providers were probed.

SelectorKeyRecord
googleRSA 2048-bit OKv=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwf0XKEl9Q3GEcvlF61Mwn1r2tm8G…
k1RSA 1024-bit Weakv=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCj1R+dW6F1JtKjV19LIfRuMNNmhGuq1QqG…
k2RSA 2048-bit OKv=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBX…
k3RSA 2048-bit OKv=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsYGiMSn7fsUqSvfSX40x9R1OlRtb…
s1RSA 2048-bit OKk=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsGPC6A/BmqtUI/ABuZJP/2QSzn/imRO7…
s2RSA 1024-bit Weakk=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeSA8OAGc2rA3D09zdmf1qQN57HZDja/gUwNCz…
  • WarningDKIM selectors "k1", "s2" use 1024-bit keys. Rotate to 2048 bits.

DMARC OK

v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email
Policy
p=reject
Applies to
100% of failing mail
Aggregate reports
mailto:dmarc_agg@vali.email
  • OK No problems detected.

Mail exchange and extras

  • OK No problems detected.
MTA-STS
Not published optional: enforces TLS for inbound mail
TLS-RPT
Not published
BIMI
OK v=BIMI1; l=https://amplify.valimail.com/bimi/philo/wJcLPKnxsZD-Philo_BIMI_VMC.svg; a=https://amplify.valimail.com/bimi/philo/wJcLPKnxsZD-Philo_BIMI_VMC.pem

How the grade is calculated

Score 100/100. SPF present and valid. SPF ends with ~all. DKIM found (6 selectors). DKIM key is 2048-bit or stronger. DMARC present and valid. DMARC policy is reject. DMARC aggregate reporting enabled. SPF contributes up to 35 points, DKIM up to 25, DMARC up to 40 (policy strength and reporting). Any critical issue caps the grade at C. Lookups that failed are shown as "not measured" and never counted as missing.

Check another domain: