DNS & Email Security Report for belastingdienst.nl

An automated analysis of belastingdienst.nl's DNS configuration, email authentication (SPF, DKIM, DMARC), DNSSEC chain, IPv6 readiness, and transport security. Last analyzed June 10, 2026.

A91/100
Very Good

Strong security posture

Overall security score: 91/100 · Grade A (Very Good)

This report is a cached snapshot

DNS changes frequently. Run a fresh, interactive scan of belastingdienst.nl for live records, propagation, and deep checks.

Run a fresh live scan

Detailed check results

DNS

100%pass
  • A record presentcritical

    1 A record(s) found

  • AAAA record presentrecommended

    1 AAAA record(s) found

  • MX records presentrecommended

    2 MX record(s) found

  • NS records presentcritical

    3 NS record(s) found

  • SOA record presentcritical

    SOA record found

  • Multiple nameserversrecommended

    3 nameservers configured ✓

  • SOA serial formatinfo

    Serial 2006997018 (YYYYMMDDnn format)

  • SOA timers validinfo

    Refresh: 14400s ✓, Retry: 1440s ✓, Expire: 604800s ✓

  • No lame nameserversinfo

    3 NS all responding ✓

  • Glue records presentinfo

    5 glue record(s)

  • WWW record configuredinfo

    A record matches apex

  • MX servers have PTR recordsinfo

    4 MX IPs all have PTR records ✓

  • MX servers have FCrDNSinfo

    4 MX IPs have forward-confirmed reverse DNS ✓

DNSSEC

93%pass
  • DNSSEC signedrecommended

    DNSSEC is enabled ✓

  • DNSSEC validation OKcritical

    DNSSEC validates correctly ✓

  • NSEC3 RFC 9276 compliantrecommended

    NSEC3 not RFC 9276 compliant: iterations=10 (must be 0), salt="1e2d76" (must be empty). Modern resolvers may reject this zone

  • RRSIG signatures validrecommended

    RRSIG signature expires in 3 days — renewal needed

  • Modern DNSSEC algorithmoptional

    RSA/SHA-256 (algorithm 8) — acceptable ✓

  • DS digest algorithm modernrecommended

    DS digest: SHA-256 — modern ✓

  • DNSKEY algorithm secureoptional

    DNSKEY: RSA/SHA-256 — acceptable, consider ECDSA (13) or Ed25519 (15)

  • RRSIG TTL saferecommended

    Record TTLs do not exceed RRSIG validity periods ✓

  • Chain of trust completecritical

    Complete chain: DNSKEY + DS + RRSIG ✓

IPv6

100%pass
  • Website reachable via IPv6recommended

    1 AAAA record(s) ✓

  • Mail servers reachable via IPv6recommended

    2/2 MX server(s) with IPv6 ✓

  • Nameservers reachable via IPv6recommended

    2/3 NS server(s) with IPv6 ✓

Email security

80%pass
  • SPF record presentcritical

    v=spf1 redirect=_spf.belastingdienst.nl

  • SPF syntax validcritical

    SPF syntax is correct ✓

  • SPF policy strict (-all)recommended

    SPF uses ~all or ?all. Change to -all for strict enforcement

  • DKIM foundrecommended

    No DKIM found. Configure DKIM signing with your email provider

  • DMARC record presentrecommended

    v=DMARC1; p=reject; rua=mailto:[email protected]; sp=reject;

  • DMARC policy quarantine or betterrecommended

    DMARC policy: reject ✓

  • DMARC policy rejectoptional

    DMARC policy: reject ✓

  • BIMI record presentoptional

    BIMI logo: https://vmc.digicert.eu/21f1c9f4-832a-4782-bb04-620805d23c17.svg

  • BIMI configuration validoptional

    BIMI correctly configured ✓

  • MTA-STS record presentoptional

    MTA-STS configured ✓

  • MTA-STS policy enforcedoptional

    MTA-STS mode: testing. Set mode: enforce for full protection

  • MX records validcritical

    2 MX record(s) ✓

  • MX domains use DNSSECrecommended

    1/1 MX domain(s) use DNSSEC ✓

  • MX DNSSEC validation OKrecommended

    MX DNSSEC validates correctly ✓

  • Mail servers not blacklistedcritical

    1 MX server(s) checked against 16 blacklists - clean ✓

  • No critical blacklist listingscritical

    No blacklist listings ✓

Web security

91%pass
  • CAA records presentrecommended

    5 CAA record(s) ✓

  • CAA policy strictoptional

    CAA limits certificate authorities ✓

  • TLSA records (DANE)optional

    2 DANE record(s) - configured according to best practices

  • DANE configuration validoptional

    DANE records meet best practices ✓

  • No sensitive info in TXTcritical

    No sensitive data leaked ✓

  • Verification records reviewedinfo

    3 verification record(s): Microsoft 365, Google, Adobe IDP. Consider if all are still needed

  • HTTPS availablecritical

    HTTPS working (status 200) ✓

  • Valid certificatecritical

    Certificate chain is valid and trusted ✓

  • HTTP redirects to HTTPScritical

    HTTP automatically redirects to HTTPS ✓

  • HSTS enabledrecommended

    HSTS enabled (max-age=31536000) ✓

  • HSTS max-age >= 1 yearoptional

    max-age=31536000 (≥1 year) ✓

  • X-Frame-Options headerrecommended

    X-Frame-Options: SAMEORIGIN ✓

  • X-Content-Type-Options headerrecommended

    X-Content-Type-Options: nosniff ✓

  • Content-Security-Policy headerrecommended

    Content-Security-Policy configured ✓

  • Referrer-Policy headerrecommended

    No Referrer-Policy header. Add Referrer-Policy: strict-origin-when-cross-origin

  • security.txt presentoptional

    Contact: https://www.belastingdienst.nl/rfc2350

  • security.txt validoptional

    security.txt has required Contact and Expires fields ✓

  • HTTP/3 (QUIC) supportedoptional

    No HTTP/3 support detected No h3 in Alt-Svc header No HTTPS DNS record (type 65) QUIC probe inconclusive (Inconclusive - no QUIC reply (trigger may be dropped or UDP/443 filtered)) — not a negative signal

  • QUIC UDP reachableinfo

    QUIC probe inconclusive (no reply — trigger may be dropped or UDP/443 filtered). Not a negative signal; h3 is judged from Alt-Svc / HTTPS record

  • HTTPS DNS record (SVCB)optional

    No HTTPS DNS record (type 65). Add HTTPS record for faster HTTP/3 discovery: belastingdienst.nl IN HTTPS 1 . alpn="h3,h2"

Issues found (3)

NSEC3 parameters not RFC 9276 compliant

NSEC3 iterations must be 0 and salt must be empty per RFC 9276. Modern resolvers (Unbound 1.19+, BIND 9.19+) may treat your zone as insecure

Learn more

DKIM not found

DKIM helps verify your outgoing email

Learn more

No HTTP/3 (QUIC) support

HTTP/3 uses QUIC for faster, more resilient connections. Enable it on your web server and open UDP/443 in your firewall

Learn more

Recommendations (2)

Implement DKIM

Configure DKIM signing with your email provider and publish the DKIM public key in DNS.

Impact: Improves email deliverability and prevents spoofing

Enable HTTP/3 (QUIC)

Enable HTTP/3 for faster page loads and improved connection resilience. Nginx: add "listen 443 quic reuseport;" and "add_header Alt-Svc 'h3=":443"; ma=86400'". Caddy: HTTP/3 is enabled by default. Cloudflare: Enable under Speed → Protocol Optimization. Also add an HTTPS DNS record: example.com IN HTTPS 1 . alpn="h3,h2" Ensure UDP port 443 is open in your firewall (QUIC uses UDP, not TCP).

Impact: Faster page loads (0-RTT), better mobile performance, and connection migration between networks

About this report

IntoDNS.AI evaluates belastingdienst.nl against DNS hygiene, email authentication, and transport-security best practices, scoring each check and rolling them up into an overall grade. Results reflect public DNS as observed on June 10, 2026 and may differ from a live scan if the domain has since changed its configuration.

Want to check your own domain? Scan any domain on the homepage.

Last analyzed: June 10, 2026 · Google Public DNS