Blog
Contact
Sign in
Scan complete
E
52/100
github.com
Improved · F → E · +3
Compare
1 critical issue needs immediate attention.
10/10
checks
26
passed
finished
Scan timestamps
Created
Jul 7, 2026, 6:27 AM
Started
Jul 7, 2026, 6:27 AM
Finished
Jul 7, 2026, 6:28 AM
Updated
Jul 7, 2026, 6:27 AM
Export PDF
Re-scan
Findings by severity
33 results
1
Critical
2
High
3
Medium
1
Low
26
Pass
Report coverage
97%
20 skipped - these limit completeness.
20 skipped
All
53
Critical
1
High
2
Medium
3
Low
1
Pass
26
Skipped
20
Email
96%
Sender Authentication (SPF)
Learn how it works
Info
6/7 pass
Sender Authentication (SPF)
SPF policy does not use strict fail mode
The SPF policy does not fully reject unauthorized senders.
Medium
Domain Alignment (DMARC)
Learn how it works
Info
5/7 pass
Domain Alignment (DMARC)
DMARC policy quarantines unauthenticated mail
The DMARC policy asks receivers to treat failing mail as suspicious, but does not request full rejection.
Medium
Domain Alignment (DMARC)
DMARC alignment is relaxed
The DMARC record allows relaxed identifier alignment for DKIM or SPF.
Low
Certificate Binding (DANE)
Learn how it works
Info
1/5 pass
Certificate Binding (DANE)
No MX host TLSA zone is protected by DNSSEC
None of the MX hosts have DNSSEC on their TLSA lookup zones. DANE SMTP cannot function without DNSSEC, as sending servers will ignore TLSA records from unsigned zones.
Critical
Transport Policy (MTA-STS)
Learn how it works
Info
1/6 pass
Transport Policy (MTA-STS)
MTA-STS DNS record is missing
The domain does not publish an MTA-STS TXT record, so sending servers cannot discover or enforce an MTA-STS policy.
High
TLS Reporting (TLS-RPT)
Learn how it works
Info
1/4 pass
TLS Reporting (TLS-RPT)
No TLS-RPT record found
The domain does not publish a TLS-RPT record. Sending servers cannot report TLS errors to this domain.
High
DNS
100%
DNS Integrity (DNSSEC)
Learn how it works
Info
0/6 pass
DNS Integrity (DNSSEC)
DNSSEC is not enabled
The parent zone does not publish a DS record for this domain.
Medium
Feedback