Checks
Everything we look for.
166 conditions across 13 record types. Each one has a page saying what it means, what it costs you, how to fix it and which specification we judged it against. Nothing here is a heuristic.
SPF 36
- No SPF recordCODE RED
- Multiple SPF recordsCODE RED
- SPF record has the wrong version prefixCODE RED
- SPF exceeds the 10-lookup limitCODE RED
- Too many SPF lookups resolve to nothingCODE RED
- SPF authorises the entire internetCODE RED
- SPF includes itself in a loopCODE RED
- SPF includes a domain with no SPF recordURGENT
- SPF never says "no"URGENT
- SPF has mechanisms after "all"URGENT
- SPF uses the deprecated ptr mechanismURGENT
- SPF has both redirect= and allURGENT
- SPF contains an invalid IPv4 addressURGENT
- SPF contains an invalid IPv4 prefix lengthURGENT
- SPF contains an invalid IPv6 addressURGENT
- SPF contains an invalid IPv6 prefix lengthURGENT
- SPF contains a term receivers can’t parseCODE RED
- SPF includes the same domain more than onceURGENT
- SPF is one vendor away from breakingATTENTION
- SPF record exceeds a single DNS stringATTENTION
- SPF record is large enough to be truncatedATTENTION
- SPF contains a malformed macroATTENTION
- SPF contains an unrecognised modifierNOTE
- SPF repeats a modifierCODE RED
- SPF mechanism uses = instead of :CODE RED
- SPF redirects to a domain with no SPF recordCODE RED
- SPF redirect points back into its own chainCODE RED
- An mx mechanism resolves to more than 10 hostsCODE RED
- An a mechanism points at a name with no addressATTENTION
- An mx mechanism points at a name with no mail exchangersATTENTION
- An included record carries an exp= modifierMINOR
- SPF repeats a mechanismMINOR
- SPF uses mixed-case syntaxNOTE
- SPF record has irregular spacingNOTE
- SPF ends in softfail (~all)NOTE
- SPF authorises a private or reserved IPNOTE
DMARC 48
- No DMARC recordCODE RED
- Multiple DMARC recordsCODE RED
- DMARC record contains no policyCODE RED
- DMARC policy discovery ran out of queriesCODE RED
- DMARC policy is inherited from a parent domainURGENT
- DMARC record is behind a CNAME loopCODE RED
- DMARC CNAME points nowhereCODE RED
- DMARC version tag is wrongCODE RED
- DMARC version tag is not firstCODE RED
- DMARC record repeats a tagCODE RED
- DMARC tags are not separated correctlyCODE RED
- DMARC record cannot be parsedCODE RED
- DMARC tag names use uppercaseMINOR
- DMARC record exceeds a single DNS stringMINOR
- DMARC record is large enough to be truncatedMINOR
- DMARC record has no policy tagURGENT
- DMARC policy value is invalidCODE RED
- DMARC is monitoring only (p=none)URGENT
- DMARC quarantines instead of rejectingMINOR
- Subdomain policy value is invalidATTENTION
- Non-existent subdomain policy value is invalidATTENTION
- Subdomains are less protected than the domainURGENT
- Non-existent subdomains are less protectedURGENT
- DMARC is in test mode while claiming to enforceCODE RED
- Test mode value is invalidATTENTION
- DKIM alignment value is invalidATTENTION
- SPF alignment value is invalidATTENTION
- Strict DKIM alignment is onNOTE
- Strict SPF alignment is onNOTE
- Public suffix flag value is invalidATTENTION
- A normal domain is claiming to be a public suffixCODE RED
- DMARC record uses retired tagsMINOR
- DMARC has no reporting addressURGENT
- Enforcing DMARC with no visibilityCODE RED
- Reporting destination is missing mailto:CODE RED
- Reporting address is not a valid email addressURGENT
- Reporting URI contains unencoded charactersURGENT
- Report size limit is malformedMINOR
- Reporting destinations separated by spacesATTENTION
- Too many reporting destinationsMINOR
- Failure reporting options are invalidMINOR
- Failure report destination is missing mailto:ATTENTION
- Failure report address is not a valid email addressATTENTION
- External report destination has not authorised youCODE RED
- External authorisation record is invalidCODE RED
- External authorisation could not be checkedMINOR
- {target} is not authorised to receive your reportsATTENTION
- One reporting destination has a malformed authorisation recordATTENTION
DKIM 15
- No DKIM key found at the usual selectorsNOTE
- No DKIM key at the selector you gaveURGENT
- DKIM key at {selector} has been revokedCODE RED
- DKIM record at {selector} cannot be readCODE RED
- DKIM key at {selector} is below the minimum sizeCODE RED
- DKIM key at {selector} is only 1024 bitsATTENTION
- DKIM key at {selector} uses an unrecognised algorithmURGENT
- DKIM key at {selector} is restricted to SHA-1URGENT
- Ed25519 DKIM key at {selector} is malformedURGENT
- DKIM selector {selector} is in testing modeMINOR
- DKIM record at {selector} repeats a tagURGENT
- Multiple DKIM records at {selector}URGENT
- DKIM key at {selector} is restricted to specific servicesMINOR
- A wildcard answers every DKIM selector, with the key revokedNOTE
- A wildcard publishes the same DKIM key at every selectorURGENT
Mail servers 6
Address records 1
Reverse DNS 3
DNSSEC 3
MTA-STS 9
- No MTA-STS policyATTENTION
- MTA-STS DNS record is malformedATTENTION
- MTA-STS policy file cannot be fetchedURGENT
- MTA-STS policy file redirectsURGENT
- MTA-STS policy file is malformedURGENT
- MTA-STS is in testing modeMINOR
- MTA-STS policy is switched offATTENTION
- MTA-STS policy does not list your mail serversCODE RED
- MTA-STS max_age is outside the sensible rangeMINOR
TLS-RPT 3
BIMI 14
- No BIMI recordNOTE
- BIMI published without DMARC enforcementURGENT
- BIMI record is malformedATTENTION
- BIMI logo is not served over HTTPSATTENTION
- BIMI has no verified mark certificateMINOR
- BIMI record declines participationNOTE
- The BIMI logo cannot be fetchedURGENT
- The logo is not SVG Tiny Portable SecureURGENT
- The logo has no title elementMINOR
- The logo is not squareATTENTION
- The logo contains constructs the profile forbidsURGENT
- The BIMI certificate cannot be fetchedURGENT
- The BIMI certificate has expiredCODE RED
- The BIMI certificate expires soonATTENTION
CAA 3
DMARC reports 22
- Somebody is sending as you, and it is being deliveredCODE RED
- Unauthenticated mail is getting past your policyURGENT
- Your policy stopped forged mailNOTE
- Your own mail is failing authenticationURGENT
- You are ready to turn enforcement onNOTE
- Reports are arriving, but nothing is being stoppedURGENT
- Quarantine is doing its job, go to rejectNOTE
- Not one message in these reports authenticatedCODE RED
- Some senders pass on SPF aloneATTENTION
- Some of this is forwarded mail, not an attackNOTE
- Your DKIM signatures are being broken on the wayMINOR
- Your policy only applies to part of your mailATTENTION
- Your DMARC record is still marked as testingATTENTION
- Your subdomains are protected more weakly than your domainATTENTION
- Receivers overrode your policyMINOR
- The reporter’s verdict does not match its own evidenceMINOR
- This report contains example addressesNOTE
- Mail is being reported from private addressesMINOR
- Not enough mail here to conclude muchNOTE
- This is a narrow windowNOTE
- Your policy changed during this windowNOTE
- The reporter recorded a problem of its ownNOTE
Every fix on this site is yours to implement. If you would rather someone did it, I take this work directly.