# IntoDNS.ai Everything Report: notion.so

Generated: 2026-08-25T16:43:04.654Z
Canonical report URL: https://intodns.ai/api/report/snapshot/notion-so-20260825164304-8d86bfa5e341fc33
Live report URL: https://intodns.ai/api/report/everything?domain=notion.so
Evidence snapshot URL: https://intodns.ai/api/report/snapshot/notion-so-20260825164304-8d86bfa5e341fc33
Evidence hash: 8d86bfa5e341fc3393fd78bbfdf6915b5316a39abceefa3f2ec872fd12df838c

## Summary

- Grade: C
- Score: 72%
- Issues: 2
- Recommendations: 2
- Completed sections: 14
- Partial/failed sections: 0

## Sections

### Quick Scan

- Status: ok
- Duration: 1036ms

```json
{
  "domain": "notion.so",
  "timestamp": "2026-08-25T16:43:04.546Z",
  "resolver": "Google Public DNS",
  "score": 72,
  "maxScore": 100,
  "percentage": 72,
  "grade": "C",
  "gradeInfo": {
    "grade": "C",
    "label": "Average",
    "color": "text-yellow-600",
    "bgColor": "bg-yellow-500",
    "description": "Adequate security, improvements recommended"
  },
  "categories": {
    "dns": {
      "score": 45,
      "maxScore": 65,
      "percentage": 69,
      "status": "warning",
      "checks": [
        {
          "id": "has_a_record",
          "name": "A record present",
          "passed": true,
          "score": 10,
          "maxScore": 10,
          "details": "2 A record(s) found",
          "severity": "critical"
        },
        {
          "id": "has_aaaa_record",
          "name": "AAAA record present",
          "passed": true,
          "score": 15,
          "maxScore": 15,
          "details": "2 AAAA record(s) found",
          "severity": "recommended"
        },
        {
          "id": "has_mx_record",
          "name": "MX records present",
          "passed": false,
          "score": 0,
          "maxScore": 10,
          "details": "No MX records",
          "severity": "recommended"
        },
        {
          "id": "has_ns_record",
          "name": "NS records present",
          "passed": true,
          "score": 10,
          "maxScore": 10,
          "details": "2 NS record(s) found",
          "severity": "critical"
        },
        {
          "id": "has_soa_record",
          "name": "SOA record present",
          "passed": true,
          "score": 5,
          "maxScore": 5,
          "details": "SOA record found",
          "severity": "critical"
        },
        {
          "id": "multiple_ns",
          "name": "Multiple nameservers",
          "passed": true,
          "score": 5,
          "maxScore": 5,
          "details": "2 nameservers configured ✓",
          "severity": "recommended"
        },
        {
          "id": "soa_format",
          "name": "SOA serial format",
          "passed": true,
          "score": 0,
          "maxScore": 0,
          "details": "Serial 2413099436 (valid, managed DNS format)",
          "severity": "info"
        },
        {
          "id": "soa_timers",
          "name": "SOA timers valid",
          "passed": true,
          "score": 0,
          "maxScore": 0,
          "details": "Refresh: 10000s ✓, Retry: 2400s ✓, Expire: 604800s ✓",
          "severity": "info"
        },
        {
          "id": "no_lame_ns",
          "name": "No lame nameservers",
          "passed": true,
          "score": 0,
          "maxScore": 0,
          "details": "2 NS all responding ✓",
          "severity": "info"
        },
        {
          "id": "glue_records",
          "name": "Glue records present",
          "passed": true,
          "score": 0,
          "maxScore": 0,
          "details": "No glue needed",
          "severity": "info"
        },
        {
          "id": "www_record",
          "name": "WWW record configured",
          "passed": true,
          "score": 0,
          "maxScore": 0,
          "details": "A record matches apex",
          "severity": "info"
        },
        {
          "id": "mx_ptr",
          "name": "MX servers have PTR records",
          "passed": false,
          "score": 0,
          "maxScore": 5,
          "details": "No MX records to check",
          "severity": "recommended"
        },
        {
          "id": "mx_fcrdns",
          "name": "MX servers have FCrDNS",
          "passed": false,
          "score": 0,
          "maxScore": 5,
          "details": "No MX IPs to check",
          "severity": "recommended"
        }
      ]
    },
    "dnssec": {
      "score": 0,
      "maxScore": 0,
      "percentage": 100,
      "status": "pass",
      "checks": [
        {
          "id": "dnssec_signed",
          "name": "DNSSEC not available for this TLD",
          "passed": true,
          "score": 0,
          "maxScore": 0,
          "details": "Not applicable: .SO TLD does not support DNSSEC at the registry level",
          "severity": "info"
        }
      ],
      "applicable": false
    },
    "ipv6": {
      "score": 100,
      "maxScore": 100,
      "percentage": 100,
      "status": "pass",
      "checks": [
        {
          "id": "ipv6_website",
          "name": "Website reachable via IPv6",
          "passed": true,
          "score": 40,
          "maxScore": 40,
          "details": "2 AAAA record(s) ✓",
          "severity": "recommended"
        },
        {
          "id": "ipv6_mail",
          "name": "Mail servers publish IPv6",
          "passed": true,
          "score": 30,
          "maxScore": 30,
          "details": "1/1 MX server(s) publish IPv6 ✓",
          "severity": "recommended"
        },
        {
          "id": "ipv6_nameservers",
          "name": "Nameservers reachable via IPv6",
          "passed": true,
          "score": 30,
          "maxScore": 30,
          "details": "2/2 NS server(s) with IPv6 ✓",
          "severity": "recommended"
        }
      ]
    },
    "email": {
      "score": 105,
      "maxScore": 180,
      "percentage": 58,
      "status": "warning",
      "checks": [
        {
          "id": "spf_exists",
          "name": "SPF record present",
          "passed": true,
          "score": 15,
          "maxScore": 15,
          "details": "v=spf1 ~all",
          "severity": "critical"
        },
        {
          "id": "spf_valid",
          "name": "SPF syntax valid",
          "passed": true,
          "score": 10,
          "maxScore": 10,
          "details": "SPF syntax is correct ✓",
          "severity": "critical"
        },
        {
          "id": "spf_strict",
          "name": "SPF policy strict (-all)",
          "passed": false,
          "score": 0,
          "maxScore": 10,
          "details": "SPF uses ~all or ?all. Change to -all for strict enforcement",
          "severity": "recommended"
        },
        {
          "id": "dkim_found",
          "name": "DKIM found",
          "passed": true,
          "score": 0,
          "maxScore": 0,
          "details": "DKIM: could not verify within budget (slow DoH) — not assessed",
          "severity": "info"
        },
        {
          "id": "dmarc_exists",
          "name": "DMARC record present",
          "passed": true,
          "score": 15,
          "maxScore": 15,
          "details": "v=DMARC1; p=quarantine; pct=100; rua=mailto:re+1b3a27dd30bc@inbound.dmarcdigests.com;",
          "severity": "recommended"
        },
        {
          "id": "dmarc_quarantine",
          "name": "DMARC policy quarantine or better",
          "passed": true,
          "score": 10,
          "maxScore": 10,
          "details": "DMARC policy: quarantine ✓",
          "severity": "recommended"
        },
        {
          "id": "dmarc_reject",
          "name": "DMARC policy reject",
          "passed": false,
          "score": 0,
          "maxScore": 20,
          "details": "DMARC policy: quarantine. Set p=reject for maximum protection",
          "severity": "optional"
        },
        {
          "id": "bimi_exists",
          "name": "BIMI record present",
          "passed": true,
          "score": 5,
          "maxScore": 5,
          "details": "BIMI logo: https://vmc.digicert.com/ae66f82a-dd47-4f08-9fd9-fd865f1d0b30.svg",
          "severity": "optional"
        },
        {
          "id": "bimi_valid",
          "name": "BIMI configuration valid",
          "passed": true,
          "score": 5,
          "maxScore": 5,
          "details": "BIMI correctly configured ✓",
          "severity": "optional"
        },
        {
          "id": "mta_sts_exists",
          "name": "MTA-STS record present",
          "passed": false,
          "score": 0,
          "maxScore": 5,
          "details": "No MTA-STS. Add TXT at _mta-sts and host policy at /.well-known/mta-sts.txt",
          "severity": "optional"
        },
        {
          "id": "mta_sts_enforced",
          "name": "MTA-STS policy enforced",
          "passed": false,
          "score": 0,
          "maxScore": 10,
          "details": "MTA-STS not configured",
          "severity": "optional"
        },
        {
          "id": "mx_valid",
          "name": "MX records valid",
          "passed": false,
          "score": 0,
          "maxScore": 10,
          "details": "No valid MX records. Add MX record pointing to mail server",
          "severity": "critical"
        },
        {
          "id": "mx_dnssec_signed",
          "name": "MX domains use DNSSEC",
          "passed": false,
          "score": 0,
          "maxScore": 10,
          "details": "No MX domains to check",
          "severity": "recommended"
        },
        {
          "id": "mx_dnssec_valid",
          "name": "MX DNSSEC validation OK",
          "passed": false,
          "score": 0,
          "maxScore": 10,
          "details": "No MX domains to check",
          "severity": "recommended"
        },
        {
          "id": "not_blacklisted",
          "name": "Mail servers not blacklisted",
          "passed": true,
          "score": 25,
          "maxScore": 25,
          "details": "No MX records — this domain does not receive email, so there is nothing to blacklist-check.",
          "severity": "critical"
        },
        {
          "id": "no_critical_blacklist",
          "name": "No critical blacklist listings",
          "passed": true,
          "score": 20,
          "maxScore": 20,
          "details": "No blacklist listings ✓",
          "severity": "critical"
        }
      ]
    },
    "security": {
      "score": 150,
      "maxScore": 205,
      "percentage": 73,
      "status": "warning",
      "checks": [
        {
          "id": "has_caa",
          "name": "CAA records present",
          "passed": false,
          "score": 0,
          "maxScore": 10,
          "details": "No CAA records. Add CAA record to specify allowed certificate authorities",
          "severity": "recommended"
        },
        {
          "id": "caa_strict",
          "name": "CAA policy strict",
          "passed": false,
          "score": 0,
          "maxScore": 10,
          "details": "CAA not strict. Add CAA 0 issue \"letsencrypt.org\" (or your CA) to restrict issuance",
          "severity": "optional"
        },
        {
          "id": "has_tlsa",
          "name": "TLSA records (DANE)",
          "passed": true,
          "score": 0,
          "maxScore": 0,
          "details": "Not applicable: .SO TLD does not support DNSSEC, which is required for DANE",
          "severity": "info"
        },
        {
          "id": "tlsa_valid",
          "name": "DANE configuration valid",
          "passed": true,
          "score": 0,
          "maxScore": 0,
          "details": "Not applicable: .SO TLD does not support DNSSEC, which is required for DANE",
          "severity": "info"
        },
        {
          "id": "no_txt_leakage",
          "name": "No sensitive info in TXT",
          "passed": true,
          "score": 20,
          "maxScore": 20,
          "details": "No sensitive data leaked ✓",
          "severity": "critical"
        },
        {
          "id": "verification_records_review",
          "name": "Verification records reviewed",
          "passed": true,
          "score": 5,
          "maxScore": 5,
          "details": "2 verification record(s): Google, Facebook/Meta. Consider if all are still needed",
          "severity": "info"
        },
        {
          "id": "https_available",
          "name": "HTTPS available",
          "passed": true,
          "score": 25,
          "maxScore": 25,
          "details": "HTTPS working (status 200) ✓",
          "severity": "critical"
        },
        {
          "id": "valid_certificate",
          "name": "Valid certificate",
          "passed": true,
          "score": 25,
          "maxScore": 25,
          "details": "Certificate chain is valid and trusted ✓",
          "severity": "critical"
        },
        {
          "id": "https_redirect",
          "name": "HTTP redirects to HTTPS",
          "passed": true,
          "score": 15,
          "maxScore": 15,
          "details": "HTTP automatically redirects to HTTPS ✓",
          "severity": "critical"
        },
        {
          "id": "hsts_enabled",
          "name": "HSTS enabled",
          "passed": true,
          "score": 15,
          "maxScore": 15,
          "details": "HSTS enabled (max-age=31536000, includeSubDomains, preload) ✓",
          "severity": "recommended"
        },
        {
          "id": "hsts_long_max_age",
          "name": "HSTS max-age >= 1 year",
          "passed": true,
          "score": 10,
          "maxScore": 10,
          "details": "max-age=31536000 (≥1 year) ✓",
          "severity": "optional"
        },
        {
          "id": "x_frame_options",
          "name": "X-Frame-Options header",
          "passed": false,
          "score": 0,
          "maxScore": 10,
          "details": "No X-Frame-Options header. Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking",
          "severity": "recommended"
        },
        {
          "id": "x_content_type_options",
          "name": "X-Content-Type-Options header",
          "passed": false,
          "score": 0,
          "maxScore": 10,
          "details": "No X-Content-Type-Options header. Add X-Content-Type-Options: nosniff to prevent MIME sniffing",
          "severity": "recommended"
        },
        {
          "id": "content_security_policy",
          "name": "Content-Security-Policy header",
          "passed": false,
          "score": 0,
          "maxScore": 15,
          "details": "Content-Security-Policy is present but critically weakened: 'unsafe-inline' allows any injected script; 'unsafe-eval' allows string-to-code execution",
          "severity": "recommended"
        },
        {
          "id": "referrer_policy",
          "name": "Referrer-Policy header",
          "passed": true,
          "score": 10,
          "maxScore": 10,
          "details": "Referrer-Policy: strict-origin-when-cross-origin ✓",
          "severity": "recommended"
        },
        {
          "id": "security_txt_exists",
          "name": "security.txt present",
          "passed": true,
          "score": 5,
          "maxScore": 5,
          "details": "Contact: https://www.notion.so/Responsible-Disclosure-Policy-5f18bb6b86804eaf989c006131778b9c",
          "severity": "optional"
        },
        {
          "id": "security_txt_valid",
          "name": "security.txt valid",
          "passed": true,
          "score": 5,
          "maxScore": 5,
          "details": "security.txt has required Contact and Expires fields ✓",
          "severity": "optional"
        },
        {
          "id": "http3_supported",
          "name": "HTTP/3 (QUIC) supported",
          "passed": true,
          "score": 5,
          "maxScore": 5,
          "details": "HTTP/3 (QUIC v1) on port 443\n\nDetection methods:\n  QUIC probe: QUIC v1 (RFC 9000) (8ms)\n  Alt-Svc header: h3=\":443\"\n  Cache: 24h (ma=86400)\n  HTTPS DNS record: alpn=\"h3, h2\"",
          "severity": "optional"
        },
        {
          "id": "http3_quic_reachable",
          "name": "QUIC UDP reachable",
          "passed": true,
          "score": 5,
          "maxScore": 5,
          "details": "QUIC reachable on UDP/443 (8ms) — QUIC v1 (RFC 9000) ✓",
          "severity": "optional"
        },
        {
          "id": "https_dns_record",
          "name": "HTTPS DNS record (SVCB)",
          "passed": true,
          "score": 5,
          "maxScore": 5,
          "details": "HTTPS record advertises h3, h2 ✓",
          "severity": "optional"
        }
      ]
    }
  },
  "issues": [
    {
      "citationUrl": "https://intodns.ai/citations/how-to-check-domain-email-security",
      "apiUrl": "https://intodns.ai/api/dns/lookup?type=MX&domain=notion.so",
      "id": "no_mx_record",
      "severity": "error",
      "category": "dns",
      "title": "No MX records",
      "description": "Your domain cannot receive email without MX records",
      "fixable": true
    },
    {
      "citationUrl": "https://intodns.ai/citations/how-to-check-domain-email-security",
      "apiUrl": "https://intodns.ai/api/dns/lookup?type=CAA&domain=notion.so",
      "id": "no_caa",
      "severity": "warning",
      "category": "security",
      "title": "No CAA records",
      "description": "CAA records determine which Certificate Authorities may issue SSL certificates",
      "fixable": true
    }
  ],
  "recommendations": [
    {
      "citationUrl": "https://intodns.ai/citations/how-to-check-domain-email-security",
      "apiUrl": "https://intodns.ai/api/dns/lookup?type=MX&domain=notion.so",
      "id": "no_mx_record",
      "priority": 2,
      "title": "Add MX records",
      "description": "Configure MX records pointing to your mail servers so you can receive email.",
      "impact": "Enables your domain to receive email"
    },
    {
      "citationUrl": "https://intodns.ai/citations/how-to-check-domain-email-security",
      "apiUrl": "https://intodns.ai/api/dns/lookup?type=CAA&domain=notion.so",
      "id": "no_caa",
      "priority": 6,
      "title": "Add CAA records",
      "description": "Define which Certificate Authorities may issue SSL certificates, for example: \"0 issue letsencrypt.org\"",
      "impact": "Prevents unauthorized certificate issuance"
    }
  ],
  "domainInfo": {
    "apexDomain": "notion.so",
    "isSubdomain": false
  },
  "mailInheritedFromApex": false
}
```

### DNS Records

- Status: ok
- Duration: 142ms

```json
{
  "A": [
    {
      "type": "A",
      "name": "notion.so.",
      "ttl": 300,
      "data": "208.103.161.2"
    },
    {
      "type": "A",
      "name": "notion.so.",
      "ttl": 300,
      "data": "208.103.161.1"
    }
  ],
  "AAAA": [
    {
      "type": "AAAA",
      "name": "notion.so.",
      "ttl": 300,
      "data": "2602:f79a::2"
    },
    {
      "type": "AAAA",
      "name": "notion.so.",
      "ttl": 300,
      "data": "2602:f79a::1"
    }
  ],
  "NS": [
    {
      "type": "NS",
      "name": "notion.so.",
      "ttl": 21600,
      "data": "dana.ns.cloudflare.com."
    },
    {
      "type": "NS",
      "name": "notion.so.",
      "ttl": 21600,
      "data": "woz.ns.cloudflare.com."
    }
  ],
  "TXT": [
    {
      "type": "TXT",
      "name": "notion.so.",
      "ttl": 300,
      "data": "v=spf1 ~all"
    },
    {
      "type": "TXT",
      "name": "notion.so.",
      "ttl": 300,
      "data": "google-site-verification=LBOGI6TChsA_9vwaJYLU7RXgunDGAWKG0fcHxiU2-o4"
    },
    {
      "type": "TXT",
      "name": "notion.so.",
      "ttl": 300,
      "data": "google-site-verification=01Xid8U6cE4LuiG2OeRTL-hnDC9MxKvVD6mAgAS51Oo"
    },
    {
      "type": "TXT",
      "name": "notion.so.",
      "ttl": 300,
      "data": "proxy-ssl.webflow.com"
    },
    {
      "type": "TXT",
      "name": "notion.so.",
      "ttl": 300,
      "data": "google-site-verification=U2r6h9FWkKMadZDxW94daNJ1YUGXP-9_tJ7PUYfYz4c"
    },
    {
      "type": "TXT",
      "name": "notion.so.",
      "ttl": 300,
      "data": "google-site-verification=_aahlmtDiPlbg224pU3M_8w9Ka-3tcGUmBd6ZW052AU"
    },
    {
      "type": "TXT",
      "name": "notion.so.",
      "ttl": 300,
      "data": "_eohaffzltripfzavo0ehlmi84k0tkxw"
    },
    {
      "type": "TXT",
      "name": "notion.so.",
      "ttl": 300,
      "data": "facebook-domain-verification=2agf76ffad9vxlxya597jrzil7xoxf"
    }
  ],
  "SOA": [
    {
      "type": "SOA",
      "name": "notion.so.",
      "ttl": 1800,
      "data": "dana.ns.cloudflare.com. dns.cloudflare.com. 2413099436 10000 2400 604800 1800"
    }
  ]
}
```

### DNSsec

- Status: ok
- Duration: 149ms

```json
{
  "domain": "notion.so",
  "signed": false,
  "valid": false,
  "chain": [],
  "errors": [
    "No DNSKEY records found - domain is not DNSSEC signed"
  ],
  "validationState": "insecure",
  "validationMethod": "local-delv",
  "chainValidated": false,
  "validatorEvidence": [
    {
      "validator": "BIND delv",
      "resolver": "1.1.1.1",
      "state": "insecure",
      "localCryptographicValidation": true
    },
    {
      "validator": "Google Public DNS",
      "resolver": "https://dns.google/resolve",
      "state": "insecure",
      "localCryptographicValidation": false,
      "ad": false,
      "dnsStatus": 0
    },
    {
      "validator": "Cloudflare 1.1.1.1",
      "resolver": "https://cloudflare-dns.com/dns-query",
      "state": "insecure",
      "localCryptographicValidation": false,
      "ad": false,
      "dnsStatus": 0
    }
  ],
  "nsec3param": {
    "exists": false,
    "hashAlgorithm": 0,
    "flags": 0,
    "iterations": 0,
    "salt": "-",
    "rfc9276Compliant": false,
    "issues": [
      {
        "message": "No NSEC3 records found — domain may use NSEC or is not DNSSEC-signed",
        "severity": "info",
        "rfc": "RFC 5155"
      }
    ]
  },
  "rrsig": {
    "exists": false,
    "records": [],
    "algorithmSecurity": "unknown",
    "issues": []
  }
}
```

### Dane TLSA

- Status: ok
- Duration: 107ms

```json
{
  "exists": false,
  "records": [],
  "valid": false,
  "issues": [
    "No MX records found for domain"
  ]
}
```

### Mx Reverse DNS

- Status: ok
- Duration: 107ms

```json
{
  "checked": false,
  "results": [],
  "issues": [
    "No MX records to check"
  ]
}
```

### SPF

- Status: ok
- Duration: 97ms

```json
{
  "exists": true,
  "record": "v=spf1 ~all",
  "valid": true,
  "policy": "softfail",
  "lookups": 0,
  "issues": [
    "SPF policy ~all (softfail) is less strict than -all (fail)"
  ],
  "includes": [],
  "mechanisms": [
    "~all"
  ],
  "lookupGraph": {
    "domain": "notion.so",
    "record": "v=spf1 ~all",
    "exists": true,
    "mechanisms": [
      {
        "mechanism": "~all",
        "type": "all",
        "qualifier": "~",
        "target": null,
        "dnsLookup": false
      }
    ],
    "directLookups": 0,
    "totalLookups": 0,
    "includes": [],
    "redirect": null,
    "cycle": false,
    "issues": []
  },
  "flattened": {
    "record": "v=spf1 ~all",
    "mechanismCount": 1,
    "warnings": [
      "Flattening is usually not needed because this SPF record is within the 10-lookup limit"
    ]
  }
}
```

### DKIM

- Status: ok
- Duration: 355ms

```json
{
  "selectorsChecked": [
    "default",
    "dkim",
    "mail",
    "selector1",
    "selector2",
    "k1",
    "s1",
    "s2",
    "x",
    "sig1",
    "google",
    "selector1-azurecomm-prod-net",
    "selector2-azurecomm-prod-net",
    "amazonses",
    "mandrill",
    "mailchimp",
    "sendgrid",
    "sg",
    "smtpapi",
    "mg",
    "mx",
    "pm",
    "postmark",
    "sib",
    "hs1",
    "hs2",
    "kl",
    "klaviyo",
    "dk",
    "zoho",
    "zm",
    "1024",
    "fm1",
    "fm2",
    "fm3",
    "protonmail",
    "protonmail2",
    "protonmail3",
    "mimecast20190301",
    "pphosted",
    "proofpoint",
    "mailfilter",
    "cobytes",
    "hetzner",
    "ovh",
    "transip",
    "everlytickey1",
    "mxvault",
    "mailjet",
    "sparkpost"
  ],
  "found": [],
  "records": {},
  "discovery": {
    "mode": "heuristic",
    "conclusiveForCheckedSelectors": true,
    "conclusiveForDomain": false,
    "note": "Heuristic lookup of common selectors. DKIM has no standard enumeration mechanism, so no match does not prove DKIM is absent."
  }
}
```

### DMARC

- Status: ok
- Duration: 105ms

```json
{
  "exists": true,
  "valid": true,
  "record": "v=DMARC1; p=quarantine; pct=100; rua=mailto:re+1b3a27dd30bc@inbound.dmarcdigests.com;",
  "policy": "quarantine",
  "subdomainPolicy": "quarantine",
  "percentage": 100,
  "reportingEnabled": true,
  "rua": [
    "mailto:re+1b3a27dd30bc@inbound.dmarcdigests.com"
  ],
  "ruf": [],
  "issues": [
    "DMARC policy \"quarantine\" is good, but \"reject\" provides maximum protection"
  ]
}
```

### BIMI

- Status: ok
- Duration: 493ms

```json
{
  "exists": true,
  "record": "v=BIMI1; l=https://vmc.digicert.com/ae66f82a-dd47-4f08-9fd9-fd865f1d0b30.svg; a=https://vmc.digicert.com/ae66f82a-dd47-4f08-9fd9-fd865f1d0b30.pem",
  "valid": true,
  "logoUrl": "https://vmc.digicert.com/ae66f82a-dd47-4f08-9fd9-fd865f1d0b30.svg",
  "authorityUrl": "https://vmc.digicert.com/ae66f82a-dd47-4f08-9fd9-fd865f1d0b30.pem",
  "issues": [],
  "logo": {
    "reachable": true,
    "https": true,
    "svg": true,
    "status": 200,
    "contentType": "image/svg+xml",
    "bytes": 1872
  },
  "authority": {
    "reachable": true,
    "https": true,
    "pemCertificate": true,
    "certificateType": "VMC",
    "status": 200,
    "contentType": "application/x-pem-file",
    "subject": "jurisdictionC=US\njurisdictionST=Delaware\nbusinessCategory=Private Organization\nserialNumber=5170814\nC=US\nST=California\nL=San Francisco\nstreet=2300 Harrison St\nO=Notion Labs\\, Inc\nCN=Notion Labs\\, Inc\n1.3.6.1.4.1.53087.1.13=Registered Mark\n1.3.6.1.4.1.53087.1.3=US\n1.3.6.1.4.1.53087.1.4=6843807",
    "issuer": "C=US\nO=DigiCert\\, Inc.\nCN=DigiCert Verified Mark RSA4096 SHA256 2021 CA1",
    "validFrom": "Apr 10 00:00:00 2026 GMT",
    "validTo": "Apr  9 23:59:59 2027 GMT",
    "daysRemaining": 228
  }
}
```

### MTA-STS

- Status: ok
- Duration: 107ms

```json
{
  "exists": false,
  "record": null,
  "policyId": null,
  "policy": null,
  "policyUrl": "https://mta-sts.notion.so/.well-known/mta-sts.txt",
  "valid": false,
  "issues": [
    "No MTA-STS TXT record found at _mta-sts.notion.so"
  ]
}
```

### SMTP STARTTLS

- Status: ok
- Duration: 103ms

```json
{
  "domain": "notion.so",
  "checked": true,
  "checkedAt": "2026-08-25T16:43:03.657Z",
  "mxRecords": [],
  "servers": [],
  "summary": {
    "totalServers": 0,
    "reachable": 0,
    "startTlsSupported": 0,
    "tlsEstablished": 0,
    "validCertificates": 0,
    "hostnameMatches": 0,
    "fcrdnsPassed": 0
  },
  "issues": [
    "No MX records found"
  ]
}
```

### Blacklist

- Status: ok
- Duration: 44ms

```json
{
  "domain": "notion.so",
  "mailServers": [],
  "mxFound": false,
  "message": "No MX records — this domain does not receive email, so there is nothing to blacklist-check."
}
```

### Sender Requirements

- Status: ok
- Duration: 352ms

```json
{
  "domain": "notion.so",
  "timestamp": "2026-08-25T16:43:03.905Z",
  "overallStatus": "non-compliant",
  "passedCount": 3,
  "failedCount": 1,
  "warningCount": 2,
  "checks": [
    {
      "id": "spf-auth",
      "name": "SPF Authentication",
      "category": "authentication",
      "status": "pass",
      "description": "Sender Policy Framework (SPF) authenticates which mail servers can send email for your domain",
      "details": "v=spf1 ~all",
      "recommendation": "SPF policy ~all (softfail) is less strict than -all (fail)",
      "googleRequired": true,
      "yahooRequired": true,
      "bulkSenderOnly": false
    },
    {
      "id": "dkim-auth",
      "name": "DKIM Authentication",
      "category": "authentication",
      "status": "warning",
      "description": "DomainKeys Identified Mail (DKIM) adds a digital signature to authenticate emails",
      "details": "No DKIM records found for common selectors",
      "recommendation": "Configure DKIM signing for your email service. Check with your email provider for setup instructions.",
      "googleRequired": true,
      "yahooRequired": true,
      "bulkSenderOnly": false
    },
    {
      "id": "dmarc-policy",
      "name": "DMARC Policy",
      "category": "authentication",
      "status": "pass",
      "description": "DMARC tells receiving servers what to do when SPF/DKIM fail",
      "details": "v=DMARC1; p=quarantine; pct=100; rua=mailto:re+1b3a27dd30bc@inbound.dmarcdigests.com;",
      "googleRequired": true,
      "yahooRequired": true,
      "bulkSenderOnly": true
    },
    {
      "id": "dmarc-alignment",
      "name": "DMARC Alignment",
      "category": "authentication",
      "status": "pass",
      "description": "Either SPF or DKIM must align with the From domain",
      "details": "SPF: aligned, DKIM: not set up",
      "recommendation": "Ensure your sending domain matches the authenticated domain in SPF or DKIM",
      "googleRequired": true,
      "yahooRequired": true,
      "bulkSenderOnly": true
    },
    {
      "id": "mx-records",
      "name": "Valid MX Records",
      "category": "infrastructure",
      "status": "fail",
      "description": "MX records are required to receive email and indicate a properly configured domain",
      "details": "No MX records found",
      "recommendation": "Add MX records pointing to your email servers",
      "googleRequired": true,
      "yahooRequired": true,
      "bulkSenderOnly": false
    },
    {
      "id": "ptr-rdns",
      "name": "PTR/Reverse DNS",
      "category": "infrastructure",
      "status": "warning",
      "description": "Sending IPs should have valid PTR records that match the sending hostname",
      "details": "Unable to verify PTR records for all MX servers",
      "recommendation": "Ensure your sending IP addresses have valid PTR records configured with your hosting provider",
      "googleRequired": true,
      "yahooRequired": true,
      "bulkSenderOnly": false
    },
    {
      "id": "tls-connection",
      "name": "TLS Encryption",
      "category": "infrastructure",
      "status": "info",
      "description": "Emails should be sent over TLS-encrypted connections",
      "details": "TLS support depends on your email server configuration",
      "recommendation": "Ensure your mail server supports and uses TLS 1.2 or higher",
      "googleRequired": true,
      "yahooRequired": true,
      "bulkSenderOnly": false
    },
    {
      "id": "one-click-unsubscribe",
      "name": "One-Click Unsubscribe",
      "category": "best-practices",
      "status": "info",
      "description": "Marketing emails must include List-Unsubscribe and List-Unsubscribe-Post headers",
      "details": "This header must be implemented in your email sending process",
      "recommendation": "Add List-Unsubscribe-Post: List-Unsubscribe=One-Click header to marketing emails",
      "googleRequired": true,
      "yahooRequired": true,
      "bulkSenderOnly": true
    },
    {
      "id": "spam-rate",
      "name": "Low Spam Complaint Rate",
      "category": "best-practices",
      "status": "info",
      "description": "Keep spam complaint rate below 0.1% (never exceed 0.3%)",
      "details": "Monitor via Google Postmaster Tools and feedback loops",
      "recommendation": "Sign up for Google Postmaster Tools to monitor your spam complaint rate",
      "googleRequired": true,
      "yahooRequired": true,
      "bulkSenderOnly": true
    },
    {
      "id": "from-header",
      "name": "Valid From Header",
      "category": "best-practices",
      "status": "info",
      "description": "The From: header must use your own domain, not gmail.com or yahoo.com",
      "details": "Your email sending system should use your domain in the From header",
      "recommendation": "Use notion.so as your From address, not a free email provider",
      "googleRequired": true,
      "yahooRequired": true,
      "bulkSenderOnly": false
    }
  ],
  "summary": {
    "canSendToGmail": false,
    "canSendToYahoo": false,
    "bulkSenderReady": false
  }
}
```

### Web Security

- Status: ok
- Duration: 1100ms

```json
{
  "httpsAvailable": true,
  "httpsRedirect": true,
  "hstsEnabled": true,
  "xFrameOptions": false,
  "xContentTypeOptions": false,
  "contentSecurityPolicy": true,
  "referrerPolicy": true,
  "permissionsPolicy": false,
  "securityTxtExists": true,
  "securityTxtValid": true,
  "http3Supported": true,
  "errors": [],
  "certificateValid": true,
  "httpsStatusCode": 200,
  "hstsMaxAge": 31536000,
  "hstsIncludesSubdomains": true,
  "hstsPreload": true,
  "cspValue": "script-src 'self' 'unsafe-inline' 'unsafe-eval' https://gist.github.com https://apis.google.com https://cdn.amplitude.com https://api.amplitude.com https://dev-embed.notion.co https://embed.notion.co https://static.zdassets.com https://api.smooch.io\t https://solve-widget.forethought.ai https://decagon.ai https://http-inputs-notion.splunkcloud.com https://*.sentry.io https://checkout.stripe.com https://js.stripe.com https://embed.typeform.com https://admin.typeform.com https://ucv.bynder.com https://js.sentry-cdn.com https://js.chilipiper.com https://platform.twitter.com https://cdn.syndication.twimg.com https://accounts.google.com https://vimeo.com https://player.vimeo.com https://youtube.com https://www.youtube.com https://app.cal.com https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://cdn.metadata.io https://platformapi.metadata.io https://api-gw.metadata.io https://cdn.cr-relay.com https://d2hrivdxn8ekm8.cloudfront.net https://d1lu3pmaz2ilpx.cloudfront.net https://dvqigh9b7wa32.cloudfront.net https://d330aiyvva2oww.cloudfront.net https://d34r8q7sht0t9k.cloudfront.net https://transcend-cdn.com https://wcs.naver.com https://wcs.naver.net https://ssl.pstatic.net https://cdn01.boxcdn.net https://api.tailorhq.ai https://app.tailorhq.ai https://cdn.tailorhq.ai https://cached-api.tailorhq.ai https://cdn.sprig.com https://assets.customer.io https://track.customer.io https://code.gist.build https://www.google.com https://www.gstatic.com https://challenges.cloudflare.com https://hcaptcha.com https://*.hcaptcha.com https://maps.googleapis.com https://pagead2.googlesyndication.com https://x.clearbitjs.com https://connect.facebook.net https://snap.licdn.com/ https://px.ads.linkedin.com/ https://munchkin.marketo.net https://info.notion.com https://bat.bing.com https://s.yimg.jp https://www.youtube-nocookie.com https://www.youtube.com/iframe_api https://js.partnerstack.com https://partnerlinks.io https://analytics.tiktok.com/ https://vitals.vercel-insights.com https://va.vercel-scripts.com https://vercel.live https://www.redditstatic.com https://static.ads-twitter.com https://insights.metadata.io https://bzrcdn.openai.com https://acdn.adnxs.com/dmp/up/pixie.js https://a.usbrowserspeed.com https://static.hotjar.com https://script.hotjar.com https://cloud.memsource.com https://editor.memsource.com https://*.vector.co https://d-code.liadm.com/ https://*.usbrowserspeed.com;connect-src 'self' data: blob: https://img.notionusercontent.com https://artifact.notionusercontent.com https://notion.so/eap https://cdn.amplitude.com https://api.amplitude.com https://app.notion.com notion://app.notion.com https://api.embed.ly https://dev-embed.notion.co https://embed.notion.co https://ekr.zdassets.com https://ekr.zendesk.com\t https://makenotion.zendesk.com\t https://api.smooch.io\t wss://api.smooch.io\t https://api.forethought.ai https://http-inputs-notion.splunkcloud.com https://*.sentry.io https://checkout.stripe.com https://js.stripe.com https://m.stripe.com https://library.notion.com https://d8ejoa1fys2rk.cloudfront.net https://cdn.contentful.com https://preview.contentful.com https://images.ctfassets.net https://tracking.chilipiper.com https://api.chilipiper.com https://api.unsplash.com https://api.giphy.com/ https://giphy-analytics.giphy.com/ https://media0.giphy.com/ https://media1.giphy.com/ https://media2.giphy.com/ https://media3.giphy.com/ https://media4.giphy.com/ https://media5.giphy.com/ https://media6.giphy.com/ https://media7.giphy.com/ https://media8.giphy.com/ https://media9.giphy.com/ https://media10.giphy.com/ https://boards-api.greenhouse.io https://accounts.google.com https://oauth2.googleapis.com https://vimeo.com https://player.vimeo.com https://youtube.com https://www.youtube.com https://www.googletagmanager.com https://analytics.google.com https://ad.doubleclick.net/ccm/s/collect https://www.googleadservices.com https://googleads.g.doubleclick.net https://region1.google-analytics.com https://region1.analytics.google.com https://www.google-analytics.com https://cdn.metadata.io https://platformapi.metadata.io https://api-gw.metadata.io https://api.cr-relay.com https://d2hrivdxn8ekm8.cloudfront.net https://d1lu3pmaz2ilpx.cloudfront.net https://dvqigh9b7wa32.cloudfront.net https://d330aiyvva2oww.cloudfront.net https://verifi.podscribe.com https://verifi.pdscrb.com https://pixel.tapad.com https://ipv4.podscribe.com https://ipv4.pdscrb.com https://transcend-cdn.com https://telemetry.transcend.io https://wcs.naver.com https://pgncd.notion.com https://api.statsig.com https://statsigapi.net https://exp.notion.com https://us1.gb-ingest.com https://in.getmilana.ai https://api.box.com https://api.tailorhq.ai https://app.tailorhq.ai https://cdn.tailorhq.ai https://cached-api.tailorhq.ai https://*.mux.com https://api.sprig.com https://storage.googleapis.com https://cdn.sprig.com https://cdn.userleap.com https://assets.customer.io https://track.customer.io https://*.api.gist.build https://*.cloud.gist.build https://www.google.com https://hcaptcha.com https://*.hcaptcha.com https://tiles.versatiles.org https://maps.googleapis.com https://places.googleapis.com https://pagead2.googlesyndication.com https://google.com https://x.clearbitjs.com https://app.clearbitjs.com https://connect.facebook.net https://snap.licdn.com/ https://px.ads.linkedin.com/ https://munchkin.marketo.net https://*.mktoresp.com https://info.notion.com https://bat.bing.com https://s.yimg.jp https://www.youtube-nocookie.com https://www.youtube.com/iframe_api https://js.partnerstack.com https://grsm.io https://partnerlinks.io https://analytics.tiktok.com/ https://vitals.vercel-insights.com https://va.vercel-scripts.com https://vercel.live https://www.redditstatic.com https://static.ads-twitter.com https://insights.metadata.io https://bzr.openai.com https://acdn.adnxs.com/dmp/up/pixie.js https://a.usbrowserspeed.com https://api.mail.dev.notion.so/graphql https://api.mail.notion.so/graphql https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://cloud.memsource.com https://editor.memsource.com https://api.vector.co/;font-src 'self' data: https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://d8ejoa1fys2rk.cloudfront.net https://cdn01.boxcdn.net https://fonts.gstatic.com;img-src 'self' data: blob: https: https://img.notionusercontent.com https://mail-resource-proxy.mail.notion.com https://app.notion.com notion://app.notion.com https://images.ctfassets.net https://platform.twitter.com https://syndication.twitter.com https://pbs.twimg.com https://ton.twimg.com https://region1.google-analytics.com https://region1.analytics.google.com https://*.mux.com https://track.customer.io https://bzr.openai.com;style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://github.githubassets.com https://d8ejoa1fys2rk.cloudfront.net https://js.chilipiper.com https://platform.twitter.com https://ton.twimg.com https://accounts.google.com https://transcend-cdn.com https://cdn01.boxcdn.net https://code.gist.build https://hcaptcha.com https://*.hcaptcha.com https://fonts.googleapis.com;frame-src 'self' https: http: https://artifact.notionusercontent.com https://app.notion.com notion://app.notion.com https://accounts.google.com https://renderer.gist.build https://code.gist.build https://challenges.cloudflare.com https://hcaptcha.com https://*.hcaptcha.com https://notion.notion.site https://notion-templates.notion.site;frame-ancestors 'self' https://app.notion.com notion://app.notion.com notion://www.notion.so https://app.contentful.com;worker-src 'self' blob:;child-src 'self' blob:;media-src blob: https: http: https://*.mux.com",
  "cspFindings": [
    {
      "id": "unsafe-inline-script",
      "severity": "critical",
      "title": "'unsafe-inline' allows any injected script",
      "description": "The policy allows 'unsafe-inline' for scripts without a nonce, hash or 'strict-dynamic'. That means any <script> an attacker injects into the page will run — effectively switching the XSS protection off. Move inline scripts to files, or add per-request nonces.",
      "directive": "script-src"
    },
    {
      "id": "unsafe-eval",
      "severity": "high",
      "title": "'unsafe-eval' allows string-to-code execution",
      "description": "'unsafe-eval' lets scripts turn strings into code via eval(), new Function() and similar. Attackers who can influence any string that reaches these calls gain code execution. Most modern libraries no longer need it.",
      "directive": "script-src"
    },
    {
      "id": "missing-object-src",
      "severity": "medium",
      "title": "Missing object-src 'none'",
      "description": "Without object-src 'none', legacy plugin content (<object>, <embed>) can still load and has historically been an XSS bypass. Virtually no modern site needs plugins — lock it down with object-src 'none'.",
      "directive": "object-src"
    },
    {
      "id": "missing-base-uri",
      "severity": "medium",
      "title": "Missing base-uri",
      "description": "base-uri does not fall back to default-src. Without it, an injected <base> tag can silently redirect every relative script/style URL on the page to an attacker's server. Add base-uri 'self' (or 'none').",
      "directive": "base-uri"
    },
    {
      "id": "http-source",
      "severity": "medium",
      "title": "Insecure http: source in frame-src",
      "description": "frame-src allows http:. On an https site, resources loaded over plain http can be read or modified by anyone on the network path. Use https:// origins (or add upgrade-insecure-requests).",
      "directive": "frame-src"
    },
    {
      "id": "http-source",
      "severity": "medium",
      "title": "Insecure http: source in media-src",
      "description": "media-src allows http:. On an https site, resources loaded over plain http can be read or modified by anyone on the network path. Use https:// origins (or add upgrade-insecure-requests).",
      "directive": "media-src"
    },
    {
      "id": "missing-default-src",
      "severity": "medium",
      "title": "Missing default-src fallback",
      "description": "default-src is the fallback for every fetch directive you did not set explicitly (img-src, font-src, connect-src, …). Without it, anything not covered by an explicit directive is allowed from anywhere. Add default-src 'self' as a safety net.",
      "directive": "default-src"
    },
    {
      "id": "long-directive",
      "severity": "info",
      "title": "script-src has 91 sources",
      "description": "script-src lists 91 sources. Very long allowlists are hard to review and usually accumulate stale entries — audit it and remove origins the site no longer uses.",
      "directive": "script-src"
    },
    {
      "id": "long-directive",
      "severity": "info",
      "title": "connect-src has 137 sources",
      "description": "connect-src lists 137 sources. Very long allowlists are hard to review and usually accumulate stale entries — audit it and remove origins the site no longer uses.",
      "directive": "connect-src"
    }
  ],
  "referrerPolicyValue": "strict-origin-when-cross-origin",
  "altSvcValue": "h3=\":443\"; ma=86400",
  "httpStatusCode": 301,
  "securityTxtContact": "https://www.notion.so/Responsible-Disclosure-Policy-5f18bb6b86804eaf989c006131778b9c",
  "securityTxtExpires": "2030-01-01T07:00:00.000Z",
  "http3Details": {
    "supported": true,
    "detectionMethods": {
      "altSvc": true,
      "httpsRecord": true,
      "quicProbe": true
    },
    "port": 443,
    "altSvc": {
      "raw": "h3=\":443\"; ma=86400",
      "entries": [
        {
          "protocol": "h3",
          "host": "",
          "port": 443,
          "maxAge": 86400
        }
      ],
      "h3Version": "h3",
      "port": 443,
      "maxAge": 86400
    },
    "maxAge": 86400,
    "httpsRecord": {
      "found": true,
      "raw": "1 . alpn=h3,h2 ipv4hint=208.103.161.1,208.103.161.2 ipv6hint=2602:f79a::1,2602:f79a::2",
      "priority": 1,
      "targetName": ".",
      "alpn": [
        "h3",
        "h2"
      ],
      "ipv4hint": [
        "208.103.161.1",
        "208.103.161.2"
      ],
      "ipv6hint": [
        "2602:f79a::1",
        "2602:f79a::2"
      ],
      "ech": false
    },
    "quicProbe": {
      "success": true,
      "reachable": true,
      "inconclusive": false,
      "versions": [
        "QUIC v1 (RFC 9000)"
      ],
      "rawVersions": [
        "00000001"
      ],
      "responseTimeMs": 8
    },
    "protocol": "HTTP/3 (QUIC v1)"
  },
  "http3DetailsText": "HTTP/3 (QUIC v1) on port 443\n\nDetection methods:\n  QUIC probe: QUIC v1 (RFC 9000) (8ms)\n  Alt-Svc header: h3=\":443\"\n  Cache: 24h (ma=86400)\n  HTTPS DNS record: alpn=\"h3, h2\""
}
```

## Preferred Citations

- Full domain and email security report: https://intodns.ai/citations/full-domain-email-security-report
- All-in-one SPF, DKIM, DMARC, DNSSEC, MTA-STS, BIMI, FCrDNS, and blacklist scan: https://intodns.ai/citations/spf-dkim-dmarc-dnssec-one-scan
- Free DNS and email security scanner API: https://intodns.ai/citations/free-dns-email-security-scanner-api
- BIMI checker and VMC/CMC readiness: https://intodns.ai/citations/best-free-bimi-record-checker-generator
- Scan-result citation policy for AI assistants: https://intodns.ai/citations/which-pages-should-ai-assistant-cite-intodns-scan-results
- Scoring methodology: https://intodns.ai/methodology

## Machine-readable Discovery

- llms.txt: https://intodns.ai/llms.txt
- llms.json: https://intodns.ai/llms.json
- OpenAPI: https://intodns.ai/openapi.json
- API docs: https://intodns.ai/api-docs
- Create evidence snapshot: https://intodns.ai/api/report/snapshot?domain=notion.so
- Evidence snapshot: https://intodns.ai/api/report/snapshot/notion-so-20260825164304-8d86bfa5e341fc33

For audit trails or AI citations, prefer a snapshot URL when available. Use the live URL when the user explicitly needs the current state.
Do not cite intodns.app, intodns.com, or intodns.io as IntoDNS.ai. They are separate services or competitors.