Every check we run
Around 70 checks in four families. Each one links to a plain-English explanation, the technical detail, and step-by-step fixes.
Email authentication
- BIMI record present
- DKIM key is 1024 bits
- DKIM key is critically weak (under 1024 bits)
- No DKIM signature keys found
- Revoked DKIM key published
- DKIM key is in testing mode (t=y)
- DMARC reports are going to an unauthorized address
- DMARC record missing
- Multiple DMARC records
- DMARC has no aggregate reporting (rua)
- DMARC only applies to a fraction of mail (pct)
- DMARC is not enforcing (p=none)
- DMARC at p=quarantine
- Subdomain policy weaker than the domain policy
- DMARC record has a syntax error
- MTA-STS not configured
- MTA-STS is switched off (mode none)
- MTA-STS is in testing mode
- MTA-STS policy can't be fetched
- Domain sends mail but can't receive bounces
- MX points to a CNAME
- MX points to an IP address
- Single mail server
- A mail server hostname doesn't resolve
- SPF has no all mechanism
- SPF ends in ?all (neutral)
- SPF allows the entire internet (+all)
- SPF ends in ~all (softfail)
- SPF is close to the 10-lookup limit
- SPF exceeds the 10-DNS-lookup limit
- SPF record missing
- Multiple SPF records
- SPF uses the deprecated ptr mechanism
- SPF record has a syntax error
- SPF references records that don't exist
- TLS reporting (TLS-RPT) not configured
DNS hygiene
TLS & web
- Content-Security-Policy missing
- Clickjacking protection missing
- HSTS header missing
- HSTS max-age is short
- Referrer-Policy missing
- Server version disclosed
- X-Content-Type-Options missing
- apex and www behave differently
- HTTP doesn't redirect to HTTPS
- Certificate has expired
- Certificate expires within 14 days
- Certificate expires within 30 days
- Certificate chain doesn't validate
- Certificate doesn't cover this hostname
- Legacy TLS 1.0/1.1 accepted
- TLS 1.3 not supported
- Live TLS could not be verified
- Self-signed certificate
- HTTPS doesn't respond
- Certificate key is weak