Full Domain Report
Everything the DNS can tell us about a domain’s email security, in one pass — with a grade that explains itself.
DMARC, SPF and DKIM make up the grade. MTA-STS and BIMI can add to it but never subtract — a domain that gets the fundamentals right scores 100 without them. Where DKIM shows “not scored”, no key was found at a common selector, and we will not guess at a domain’s expense for a selector no tool can enumerate.
Fix these
- [DKIM] Broken key size: selector1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: selector2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: google is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: 1984 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: default is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: dkim is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mail is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: email is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: key1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: key2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: s1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: s2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: k1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: k2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: k3 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: smtp is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mx is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: x is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mandrill is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mailchimp is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sendgrid is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: s1024 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: smtpapi is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mailjet is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mailgun is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mg is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: krs is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: klaviyo is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sparkpost is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: scph0819 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: pm is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: pmta is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: hs1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: hs2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: hubspot is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sm is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sfmc is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sfdc is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: et is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: zendesk1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: zendesk2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: intercom is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: freshdesk is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: zoho is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: zohomail is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: amazonses is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: ses is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: protonmail is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: protonmail2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: protonmail3 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: fm1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: fm2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: fm3 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mesmtp is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: titan1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: titan2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: cm is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: dkimrnd is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mailer is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mailo is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: bounce is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: news is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: notify is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: noreply is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: support is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: info is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: ml is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: m1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sig1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sel1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sel2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: dk is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: dkim1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: ctct1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: ctct2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sp is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: proddkim is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: prod is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: test is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: beta is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mimecast is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mimecast20200928 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mimecast20230101 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mc is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: dkim2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: selector3 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: everlytickey1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: everlytickey2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: eversrv is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mxvault is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sig is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: sendinblue is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: brevo is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: mailerlite is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: ml1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: omnisend is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: drip is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: braze is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: iterable1 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [DKIM] Broken key size: iterable2 is 512-bitRFC 8301 forbids keys under 1024 bits and many receivers refuse to evaluate them. Rotate to 2048.
- [MTA-STS] No MTA-STS recordNothing at _mta-sts.gov.uk begins with v=STSv1. Without it senders never look for a policy, so STARTTLS stays strippable.
- [BIMI] No BIMI record foundNothing published at default._bimi.gov.uk. Mailbox providers have no logo to display for this domain.
Worth fixing
- [DMARC] Subdomains are less protected than the domainsp=none is weaker than p=reject. Attackers routinely spoof subdomains precisely because they are left unprotected.
- [MTA-STS] No TLS-RPT recordWithout _smtp._tls.gov.uk you get no reports of TLS failures, so a policy problem shows up as mail that quietly stops arriving. Publish this before switching MTA-STS to enforce.
Worth knowing
- MTA-STS is not publishedNot counted against the grade — it protects mail coming to you rather than mail claiming to be from you. Worth doing: without it, STARTTLS on your inbound mail can be stripped by anyone on the path.
- What this report does not coverBlacklist listings and exposed services are both minutes of work rather than seconds, so they are not run here. Nor is anything about mail you actually sent — for that, read an aggregate report or send a test message.
Looking good
- DMARC, SPF in good shapeOpen the individual tool for the full detail on each.
This report covers what DNS and an HTTPS fetch can answer in a few seconds. The slower checks are separate: blacklist listings, exposed services and certificates, registered lookalike domains. For what your mail actually does rather than what your records promise, send a test message or read an aggregate report.