IntoDNS.ai
ScanToolsCompareGuidesBlogPricingAPIAbout
Sign inStart your scan
IntoDNS.ai

Deterministic DNS and email security analysis with AI-assisted explanations where available. Built for developers, sysadmins and security-conscious teams.

Email testTool libraryAPI access

Product

  • Free scan
  • Free scanner
  • Tools
  • Pricing
  • API docs
  • Developers
  • MCP server
  • Security badge

Checks

  • SPF
  • DMARC
  • DKIM
  • DNSSEC
  • Blacklists
  • NIS2 readiness
  • Sender requirements
  • Email test
  • Diagnose email

Resources

  • Learn center
  • Blog
  • AI answers
  • Domain Security Reports
  • Methodology
  • Email security 2026
  • Compare tools
  • Verified domains

Company

  • About
  • Contact
  • Changelog
  • Privacy
  • Terms

© 2026 IntoDNS.ai. All rights reserved.

Deep scans via Internet.nlManaged hosting by CobytesXGitHubRSS
Back to home

7delights.in

DNS & Email Security Report

Google Public DNS

Overall Security Score

Based on DNS configuration, email security, and security checks

A
91%
Very Good

Strong security posture

dns
100%
dnssec
100%
ipv6
100%
email
85%
security
77%

Next best checks

The quick scan stays fast. Run deeper checks for mail transport, SPF complexity, BIMI readiness, or sender compliance.

NIS2 Article 21.2 readiness

Map this scan onto the ten NIS2 Article 21.2 measures and get a 0-100 readiness score with per-measure detail.

Evidence snapshot

Create a fixed Markdown report with DNS, mail, web, blacklist, sender, citation, timestamp, and hash evidence.

SMTP STARTTLS certificate

Live MX handshake, STARTTLS support, certificate trust, hostname match, and FCrDNS.

SPF lookup graph

See every include and redirect that counts toward the 10-lookup SPF limit.

BIMI logo and VMC/CMC

Validate the BIMI TXT record, hosted SVG logo, and mark-certificate URL before spending money.

FCrDNS / PTR

Check reverse DNS and forward confirmation for every mail-server IP in clustered or round-robin setups.

Sender requirements

Check Google/Yahoo/Microsoft sender expectations, blacklist posture, and authentication gaps.

Keep this domain on watch

Weekly updates and alerts keep DNS or mail changes from going unnoticed.

Score 91% – Earn a Verified Backlink

Place our badge on your website and get a dofollow backlink from our Verified Secure Domains directory.

<a href="https://intodns.ai/scan/7delights.in" target="_blank" rel="noopener noreferrer">
  <img src="https://intodns.ai/api/badge/7delights.in" alt="IntoDNS.ai Security Score for 7delights.in" />
</a>
View directory

Recommendations (4)

Improve security
  • email
    MX domains use DNSSEC
    0/1 MX domain(s) have DNSSEC. Ask your mail provider to enable DNSSEC
    -10 pts
  • email
    MX DNSSEC validation OK
    DNSSEC not enabled for MX domains
    -10 pts
  • security
    X-Frame-Options header
    No X-Frame-Options header. Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
    -10 pts
  • security
    Referrer-Policy header
    No Referrer-Policy header. Add Referrer-Policy: strict-origin-when-cross-origin
    -10 pts

Optional Features (3)

Nice to have
  • email
    MTA-STS policy enforced
    MTA-STS not configured
    -10 pts
  • security
    TLSA records (DANE)
    No TLSA/DANE records. Add TLSA at _25._tcp.mail for DANE email encryption
    -20 pts
  • security
    DANE configuration valid
    No DANE configured
    -15 pts

Passed checks (47)

  • A record present
  • AAAA record present
  • MX records present
  • NS records present
  • SOA record present
  • Multiple nameservers
  • MX servers have PTR records
  • MX servers have FCrDNS
  • DNSSEC signed
  • DNSSEC validation OK
  • NSEC3 RFC 9276 compliant
  • RRSIG signatures valid
  • Modern DNSSEC algorithm
  • DS digest algorithm modern
  • DNSKEY algorithm secure
  • RRSIG TTL safe
  • Chain of trust complete
  • Website reachable via IPv6
  • Mail servers reachable via IPv6
  • Nameservers reachable via IPv6
  • SPF record present
  • SPF syntax valid
  • SPF policy strict (-all)
  • DKIM found
  • DMARC record present
  • DMARC policy quarantine or better
  • DMARC policy reject
  • BIMI record present
  • BIMI configuration valid
  • MTA-STS record present
  • MX records valid
  • Mail servers not blacklisted
  • No critical blacklist listings
  • CAA records present
  • CAA policy strict
  • No sensitive info in TXT
  • HTTPS available
  • Valid certificate
  • HTTP redirects to HTTPS
  • HSTS enabled
  • HSTS max-age >= 1 year
  • X-Content-Type-Options header
  • Content-Security-Policy header
  • security.txt present
  • security.txt valid
  • HTTP/3 (QUIC) supported
  • HTTPS DNS record (SVCB)
Loading DNS records...

DNS Checks

A record present

Passed

An A record points your domain to the IPv4 address of your server. Without it, your website cannot be found.

OK

AAAA record present

Passed

An AAAA record points your domain to an IPv6 address. About 40% of users are on IPv6; without it they may connect slower.

OK

MX records present

Passed

An MX record tells the world which server receives email for your domain. Without it you cannot receive mail.

OK

NS records present

Passed

NS records list the name servers that answer DNS questions for your domain. They must exist for the domain to work at all.

OK

SOA record present

Passed

The SOA record holds administrative settings for your DNS zone. Every zone must have exactly one.

OK

Multiple nameservers

Passed

Having two or more name servers means your domain keeps resolving even if one name server goes down.

OK

SOA serial format

Passed

OK

SOA timers valid

Passed

OK

No lame nameservers

Passed

OK

Glue records present

Passed

OK

WWW record configured

Passed

OK

MX servers have PTR records

Passed

OK

MX servers have FCrDNS

Passed

OK

Scan History

Loading history...