IntoDNS.ai
ScanToolsCompareGuidesBlogPricingAPIAbout
Sign inStart your scan
IntoDNS.ai

Deterministic DNS and email security analysis with AI-assisted explanations where available. Built for developers, sysadmins and security-conscious teams.

Email testTool libraryAPI access

Product

  • Free scan
  • Free scanner
  • Tools
  • Pricing
  • API docs
  • Developers
  • MCP server
  • Security badge

Checks

  • SPF
  • DMARC
  • DKIM
  • DNSSEC
  • Blacklists
  • NIS2 readiness
  • Sender requirements
  • Email test
  • Diagnose email

Resources

  • Learn center
  • Blog
  • AI answers
  • Domain Security Reports
  • Methodology
  • Email security 2026
  • Compare tools
  • Verified domains

Company

  • About
  • Contact
  • Changelog
  • Privacy
  • Terms

© 2026 IntoDNS.ai. All rights reserved.

Deep scans via Internet.nlManaged hosting by CobytesXGitHubRSS
Back to home

7delights.in

DNS & Email Security Report

Google Public DNS

Overall Security Score

Based on DNS configuration, email security, and security checks

A
91%
Very Good

Strong security posture

dns
100%
dnssec
100%
ipv6
100%
email
85%
security
77%

Next best checks

The quick scan stays fast. Run deeper checks for mail transport, SPF complexity, BIMI readiness, or sender compliance.

NIS2 Article 21.2 readiness

Map this scan onto the ten NIS2 Article 21.2 measures and get a 0-100 readiness score with per-measure detail.

Evidence snapshot

Create a fixed Markdown report with DNS, mail, web, blacklist, sender, citation, timestamp, and hash evidence.

SMTP STARTTLS certificate

Live MX handshake, STARTTLS support, certificate trust, hostname match, and FCrDNS.

SPF lookup graph

See every include and redirect that counts toward the 10-lookup SPF limit.

BIMI logo and VMC/CMC

Validate the BIMI TXT record, hosted SVG logo, and mark-certificate URL before spending money.

FCrDNS / PTR

Check reverse DNS and forward confirmation for every mail-server IP in clustered or round-robin setups.

Sender requirements

Check Google/Yahoo/Microsoft sender expectations, blacklist posture, and authentication gaps.

Keep this domain on watch

Weekly updates and alerts keep DNS or mail changes from going unnoticed.

Score 91% – Earn a Verified Backlink

Place our badge on your website and get a dofollow backlink from our Verified Secure Domains directory.

<a href="https://intodns.ai/scan/7delights.in" target="_blank" rel="noopener noreferrer">
  <img src="https://intodns.ai/api/badge/7delights.in" alt="IntoDNS.ai Security Score for 7delights.in" />
</a>
View directory

Recommendations (4)

Improve security
  • email
    MX domains use DNSSEC
    0/1 MX domain(s) have DNSSEC. Ask your mail provider to enable DNSSEC
    -10 pts
  • email
    MX DNSSEC validation OK
    DNSSEC not enabled for MX domains
    -10 pts
  • security
    X-Frame-Options header
    No X-Frame-Options header. Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
    -10 pts
  • security
    Referrer-Policy header
    No Referrer-Policy header. Add Referrer-Policy: strict-origin-when-cross-origin
    -10 pts

Optional Features (3)

Nice to have
  • email
    MTA-STS policy enforced
    MTA-STS not configured
    -10 pts
  • security
    TLSA records (DANE)
    No TLSA/DANE records. Add TLSA at _25._tcp.mail for DANE email encryption
    -20 pts
  • security
    DANE configuration valid
    No DANE configured
    -15 pts

Passed checks (47)

  • A record present
  • AAAA record present
  • MX records present
  • NS records present
  • SOA record present
  • Multiple nameservers
  • MX servers have PTR records
  • MX servers have FCrDNS
  • DNSSEC signed
  • DNSSEC validation OK
  • NSEC3 RFC 9276 compliant
  • RRSIG signatures valid
  • Modern DNSSEC algorithm
  • DS digest algorithm modern
  • DNSKEY algorithm secure
  • RRSIG TTL safe
  • Chain of trust complete
  • Website reachable via IPv6
  • Mail servers publish IPv6
  • Nameservers reachable via IPv6
  • SPF record present
  • SPF syntax valid
  • SPF policy strict (-all)
  • DKIM found
  • DMARC record present
  • DMARC policy quarantine or better
  • DMARC policy reject
  • BIMI record present
  • BIMI configuration valid
  • MTA-STS record present
  • MX records valid
  • Mail servers not blacklisted
  • No critical blacklist listings
  • CAA records present
  • CAA policy strict
  • No sensitive info in TXT
  • HTTPS available
  • Valid certificate
  • HTTP redirects to HTTPS
  • HSTS enabled
  • HSTS max-age >= 1 year
  • X-Content-Type-Options header
  • Content-Security-Policy header
  • security.txt present
  • security.txt valid
  • HTTP/3 (QUIC) supported
  • HTTPS DNS record (SVCB)
Computing NIS2 readiness…

Scan History

Loading history...