DNS & Email Security Report for easydmarc.com

An automated analysis of easydmarc.com's DNS configuration, email authentication (SPF, DKIM, DMARC), DNSSEC chain, IPv6 readiness, and transport security. Last analyzed June 10, 2026.

A90/100
Very Good

Strong security posture

Overall security score: 90/100 · Grade A (Very Good)

This report is a cached snapshot

DNS changes frequently. Run a fresh, interactive scan of easydmarc.com for live records, propagation, and deep checks.

Run a fresh live scan

Detailed check results

DNS

100%pass
  • A record presentcritical

    2 A record(s) found

  • AAAA record presentrecommended

    2 AAAA record(s) found

  • MX records presentrecommended

    5 MX record(s) found

  • NS records presentcritical

    2 NS record(s) found

  • SOA record presentcritical

    SOA record found

  • Multiple nameserversrecommended

    2 nameservers configured ✓

  • SOA serial formatinfo

    Serial 2406126135 (valid, managed DNS format)

  • SOA timers validinfo

    Refresh: 10000s ✓, Retry: 2400s ✓, Expire: 604800s ✓

  • No lame nameserversinfo

    2 NS all responding ✓

  • Glue records presentinfo

    No glue needed

  • WWW record configuredinfo

    A record matches apex

  • MX servers have PTR recordsinfo

    10 MX IPs all have PTR records ✓

  • MX servers have FCrDNSinfo

    10 MX IPs have forward-confirmed reverse DNS ✓

DNSSEC

100%pass
  • DNSSEC signedrecommended

    DNSSEC is enabled ✓

  • DNSSEC validation OKcritical

    DNSSEC validates correctly ✓

  • NSEC3 RFC 9276 compliantrecommended

    Not applicable (domain uses NSEC or is not DNSSEC-signed)

  • RRSIG signatures validrecommended

    RRSIG signature expires in 1 days — renewal needed

  • Modern DNSSEC algorithmoptional

    ECDSA P-256 (algorithm 13) — modern ✓

  • DS digest algorithm modernrecommended

    DS digest: SHA-256 — modern ✓

  • DNSKEY algorithm secureoptional

    DNSKEY: ECDSA P-256 — modern ✓

  • RRSIG TTL saferecommended

    Record TTLs do not exceed RRSIG validity periods ✓

  • Chain of trust completecritical

    Complete chain: DNSKEY + DS + RRSIG ✓

IPv6

100%pass
  • Website reachable via IPv6recommended

    2 AAAA record(s) ✓

  • Mail servers reachable via IPv6recommended

    5/5 MX server(s) with IPv6 ✓

  • Nameservers reachable via IPv6recommended

    2/2 NS server(s) with IPv6 ✓

Email security

85%pass
  • SPF record presentcritical

    v=spf1 include:_spf.easydmarc_com._d.easydmarc.pro include:9358352.spf08.hubspotemail.net ~all

  • SPF syntax validcritical

    SPF syntax is correct ✓

  • SPF policy strict (-all)recommended

    SPF uses ~all or ?all. Change to -all for strict enforcement

  • DKIM foundrecommended

    DKIM selector: mail ✓

  • DMARC record presentrecommended

    v=DMARC1;p=reject;pct=100;rua=mailto:[email protected];ruf=mailto:[email protected];ri=86400;fo=1;

  • DMARC policy quarantine or betterrecommended

    DMARC policy: reject ✓

  • DMARC policy rejectoptional

    DMARC policy: reject ✓

  • BIMI record presentoptional

    BIMI logo: https://assets.easydmarc.com/c3711171be/bimi-easydmarc-com-09cde6cf.svg

  • BIMI configuration validoptional

    BIMI correctly configured ✓

  • MTA-STS record presentoptional

    MTA-STS configured ✓

  • MTA-STS policy enforcedoptional

    MTA-STS mode: enforce ✓

  • MX records validcritical

    5 MX record(s) ✓

  • MX domains use DNSSECrecommended

    0/1 MX domain(s) have DNSSEC. Ask your mail provider to enable DNSSEC

  • MX DNSSEC validation OKrecommended

    DNSSEC not enabled for MX domains

  • Mail servers not blacklistedcritical

    1 MX server(s) checked against 16 blacklists - clean ✓

  • No critical blacklist listingscritical

    No blacklist listings ✓

Web security

70%warning
  • CAA records presentrecommended

    12 CAA record(s) ✓

  • CAA policy strictoptional

    CAA limits certificate authorities ✓

  • TLSA records (DANE)optional

    No TLSA/DANE records. Add TLSA at _25._tcp.mail for DANE email encryption

  • DANE configuration validoptional

    No DANE configured

  • No sensitive info in TXTcritical

    No sensitive data leaked ✓

  • Verification records reviewedinfo

    4 verification record(s): Microsoft 365, Google, Zoom, Stripe. Consider if all are still needed

  • HTTPS availablecritical

    HTTPS working (status 200) ✓

  • Valid certificatecritical

    Certificate chain is valid and trusted ✓

  • HTTP redirects to HTTPScritical

    HTTP automatically redirects to HTTPS ✓

  • HSTS enabledrecommended

    HSTS enabled (max-age=15724800, includeSubDomains) ✓

  • HSTS max-age >= 1 yearoptional

    max-age=15724800 is too short. Set to 31536000 (1 year) or higher

  • X-Frame-Options headerrecommended

    X-Frame-Options: SAMEORIGIN ✓

  • X-Content-Type-Options headerrecommended

    X-Content-Type-Options: nosniff ✓

  • Content-Security-Policy headerrecommended

    No Content-Security-Policy header. Add CSP to prevent XSS and other injection attacks

  • Referrer-Policy headerrecommended

    No Referrer-Policy header. Add Referrer-Policy: strict-origin-when-cross-origin

  • security.txt presentoptional

    Contact: [email protected]

  • security.txt validoptional

    security.txt has required Contact and Expires fields ✓

  • HTTP/3 (QUIC) supportedoptional

    HTTP/3 (QUIC v1) on port 443 Detection methods: QUIC probe: inconclusive (no reply — trigger may be dropped or UDP/443 filtered) Alt-Svc header: h3=":443" Cache: 24h (ma=86400) HTTPS DNS record: alpn="h3, h2"

  • QUIC UDP reachableinfo

    QUIC probe inconclusive (no reply — trigger may be dropped or UDP/443 filtered). Not a negative signal; h3 is judged from Alt-Svc / HTTPS record

  • HTTPS DNS record (SVCB)optional

    HTTPS record advertises h3, h2 ✓

About this report

IntoDNS.AI evaluates easydmarc.com against DNS hygiene, email authentication, and transport-security best practices, scoring each check and rolling them up into an overall grade. Results reflect public DNS as observed on June 10, 2026 and may differ from a live scan if the domain has since changed its configuration.

Want to check your own domain? Scan any domain on the homepage.

Last analyzed: June 10, 2026 · Google Public DNS