shopify.com
Solid. A couple of things could still be tighter. 1 item below, ordered by how much inbox it is costing you.
Fix these, in this order
ranked by impactSelectors google._domainkey, mail._domainkey, pm._domainkey, m1._domainkey, smtpapi._domainkey, resend._domainkey are under 2048 bits, which some receivers already downgrade.
Do this: rotate to a 2048-bit key at the sending service.
Records found
mail._domainkey · 1024-bit
zendesk1._domainkey · 2048-bit
zendesk2._domainkey · 2048-bit
pm._domainkey · 768-bit
m1._domainkey · 1024-bit
smtpapi._domainkey · 1024-bit
resend._domainkey · 1024-bit
kl._domainkey · 2048-bit
kl2._domainkey · 2048-bit
5 alt1.aspmx.l.google.com
5 alt2.aspmx.l.google.com
10 alt3.aspmx.l.google.com
10 alt4.aspmx.l.google.com
Grade history
SPF OK
v=spf1 include:_spf.google.com include:mail.zendesk.com include:sendgrid.net ~all
- DNS lookups
- 4 of 10 allowed
- Final mechanism
~all
- OK No problems detected.
Include tree
4 / 10DKIM OK
DKIM selectors cannot be listed from DNS, so 79 selectors used by common providers were probed.
| Selector | Key | Record |
|---|---|---|
google | RSA 1024-bit Weak | v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCYb9CEvB9Fl44NTJtFQAlzmnP5ZJ7T8kdJ… |
mail | RSA 1024-bit Weak | v=DKIM1; g=*; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6FVv1tmxOilnHUpvqpf4jlVcidUZ… |
zendesk1 | RSA 2048-bit OK | v=DKIM1;t=s;n=core;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9IqdLrO3Zr2/56MHt8o… |
zendesk2 | RSA 2048-bit OK | v=DKIM1; t=s; n=core; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmiSFNkgXrO3I8aO… |
pm | RSA 768-bit Weak | v=DKIM1; k=rsa; p=MHwwDQYJKoZIhvcNAQEBBQADawAwaAJhANOtTzK6Ct6R4u976UZjFs1eiurj69J8l0P0LfRJ… |
m1 | RSA 1024-bit Weak | v=DKIM1; k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDBK1ADXLeuEWjdU55akWS9PG6TmH/… |
smtpapi | RSA 1024-bit Weak | v=DKIM1; k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9z… |
resend | RSA 1024-bit Weak | p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC0IhEE9pZDUzS7bCJuOKnG47OQ9waM9Xlv7Ve1cU+nL0tL39qy… |
kl | RSA 2048-bit OK | k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAztcABv4gl6fHyhpWbKb7Fo/F9GLERtmn… |
kl2 | RSA 2048-bit OK | k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu/TgNziu/F6lDwPHmTKXWJ2nALXeLSof… |
- WarningDKIM selectors "google", "mail", "m1", "smtpapi", "resend" use 1024-bit keys. Rotate to 2048 bits.
- WarningDKIM selector "pm" uses a 768-bit key. Keys under 1024 bits are rejected by Gmail; make sure nothing still signs with it.
DMARC OK
v=DMARC1; p=reject; pct=100; fo=1; rua=mailto:dmarc-aggregate@shopify.com;ruf=mailto:dmarc-reports@shopify.com
- Policy
p=reject- Applies to
- 100% of failing mail
- Aggregate reports
mailto:dmarc-aggregate@shopify.com
- OK No problems detected.
Mail exchange and extras
- OK No problems detected.
- MTA-STS
- Not published optional: enforces TLS for inbound mail
- TLS-RPT
- Not published
- BIMI
- OK
v=BIMI1; l=https://vmc.digicert.com/8833b699-1227-41ee-b185-cc2d9a08e213.svg; a=https://vmc.digicert.com/8833b699-1227-41ee-b185-cc2d9a08e213.pem;
How the grade is calculated
Score 100/100. SPF present and valid. SPF ends with ~all. DKIM found (10 selectors). DKIM key is 2048-bit or stronger. DMARC present and valid. DMARC policy is reject. DMARC aggregate reporting enabled. SPF contributes up to 35 points, DKIM up to 25, DMARC up to 40 (policy strength and reporting). Any critical issue caps the grade at C. Lookups that failed are shown as "not measured" and never counted as missing.
Check another domain:
Other recently graded domains
Public checks from the last few days. Every report is re-measured from DNS when opened.