IntoDNS.ai
ScanToolsCompareGuidesBlogPricingAPIAbout
Sign inStart your scan
IntoDNS.ai

Deterministic DNS and email security analysis with AI-assisted explanations where available. Built for developers, sysadmins and security-conscious teams.

Email testTool libraryAPI access

Product

  • Free scan
  • Free scanner
  • Tools
  • Pricing
  • API docs
  • Developers
  • MCP server
  • Security badge

Checks

  • SPF
  • DMARC
  • DKIM
  • DNSSEC
  • Blacklists
  • NIS2 readiness
  • Sender requirements
  • Email test
  • Diagnose email

Resources

  • Learn center
  • Blog
  • AI answers
  • Domain Security Reports
  • Methodology
  • Email security 2026
  • Compare tools
  • Verified domains

Company

  • About
  • Contact
  • Changelog
  • Privacy
  • Terms

© 2026 IntoDNS.ai. All rights reserved.

Deep scans via Internet.nlManaged hosting by CobytesXGitHubRSS
Back to home

notion.so

DNS & Email Security Report

Google Public DNS

Overall Security Score

Based on DNS configuration, email security, and security checks

C
72%
Average

Adequate security, improvements recommended

dns
69%
dnssec
N/A
ipv6
100%
email
58%
security
73%

Next best checks

The quick scan stays fast. Run deeper checks for mail transport, SPF complexity, BIMI readiness, or sender compliance.

NIS2 Article 21.2 readiness

Map this scan onto the ten NIS2 Article 21.2 measures and get a 0-100 readiness score with per-measure detail.

Evidence snapshot

Create a fixed Markdown report with DNS, mail, web, blacklist, sender, citation, timestamp, and hash evidence.

SMTP STARTTLS certificate

Live MX handshake, STARTTLS support, certificate trust, hostname match, and FCrDNS.

SPF lookup graph

See every include and redirect that counts toward the 10-lookup SPF limit.

BIMI logo and VMC/CMC

Validate the BIMI TXT record, hosted SVG logo, and mark-certificate URL before spending money.

FCrDNS / PTR

Check reverse DNS and forward confirmation for every mail-server IP in clustered or round-robin setups.

Sender requirements

Check Google/Yahoo/Microsoft sender expectations, blacklist posture, and authentication gaps.

Keep this domain on watch

Weekly updates and alerts keep DNS or mail changes from going unnoticed.

Score 72% – Earn a Verified Backlink

Place our badge on your website and get a dofollow backlink from our Verified Domains directory.

<a href="https://intodns.ai/scan/notion.so" target="_blank" rel="noopener noreferrer">
  <img src="https://intodns.ai/api/badge/notion.so" alt="IntoDNS.ai DNS and email security score for notion.so: grade C" />
</a>

Leave empty and we check your homepage and /about.

View directory

Problems (1)

Must fix
  • email
    MX records valid
    No valid MX records. Add MX record pointing to mail server
    -10 pts

Recommendations (10)

Improve security
  • dns
    MX records present
    No MX records
    -10 pts
  • dns
    MX servers have PTR records
    No MX records to check
    -5 pts
  • dns
    MX servers have FCrDNS
    No MX IPs to check
    -5 pts
  • email
    SPF policy strict (-all)
    SPF uses ~all or ?all. Change to -all for strict enforcement
    -10 pts
  • email
    MX domains use DNSSEC
    No MX domains to check
    -10 pts
  • email
    MX DNSSEC validation OK
    No MX domains to check
    -10 pts
  • security
    CAA records present
    No CAA records. Add CAA record to specify allowed certificate authorities
    -10 pts
  • security
    X-Frame-Options header
    No X-Frame-Options header. Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
    -10 pts
  • security
    X-Content-Type-Options header
    No X-Content-Type-Options header. Add X-Content-Type-Options: nosniff to prevent MIME sniffing
    -10 pts
  • security
    Content-Security-Policy header
    Content-Security-Policy is present but critically weakened: 'unsafe-inline' allows any injected script; 'unsafe-eval' allows string-to-code execution
    -15 pts

Optional Features (4)

Nice to have
  • email
    DMARC policy reject
    DMARC policy: quarantine. Set p=reject for maximum protection
    -20 pts
  • email
    MTA-STS record present
    No MTA-STS. Add TXT at _mta-sts and host policy at /.well-known/mta-sts.txt
    -5 pts
  • email
    MTA-STS policy enforced
    MTA-STS not configured
    -10 pts
  • security
    CAA policy strict
    CAA not strict. Add CAA 0 issue "letsencrypt.org" (or your CA) to restrict issuance
    -10 pts

Passed checks (28)

  • A record present
  • AAAA record present
  • NS records present
  • SOA record present
  • Multiple nameservers
  • Website reachable via IPv6
  • Mail servers publish IPv6
  • Nameservers reachable via IPv6
  • SPF record present
  • SPF syntax valid
  • DMARC record present
  • DMARC policy quarantine or better
  • BIMI record present
  • BIMI configuration valid
  • Mail servers not blacklisted
  • No critical blacklist listings
  • No sensitive info in TXT
  • HTTPS available
  • Valid certificate
  • HTTP redirects to HTTPS
  • HSTS enabled
  • HSTS max-age >= 1 year
  • Referrer-Policy header
  • security.txt present
  • security.txt valid
  • HTTP/3 (QUIC) supported
  • QUIC UDP reachable
  • HTTPS DNS record (SVCB)
Loading DNS records...

DNS Checks

A record present

Passed

An A record points your domain to the IPv4 address of your server. Without it, your website cannot be found.

OK

AAAA record present

Passed

An AAAA record points your domain to an IPv6 address. About 40% of users are on IPv6; without it they may connect slower.

OK

MX records present

No MX records

An MX record tells the world which server receives email for your domain. Without it you cannot receive mail.

Warning

NS records present

Passed

NS records list the name servers that answer DNS questions for your domain. They must exist for the domain to work at all.

OK

SOA record present

Passed

The SOA record holds administrative settings for your DNS zone. Every zone must have exactly one.

OK

Multiple nameservers

Passed

Having two or more name servers means your domain keeps resolving even if one name server goes down.

OK

SOA serial format

Passed

OK

SOA timers valid

Passed

OK

No lame nameservers

Passed

OK

Glue records present

Passed

OK

WWW record configured

Passed

OK

MX servers have PTR records

No MX records to check

Warning

MX servers have FCrDNS

No MX IPs to check

Warning

Issues (2)

  • No MX records
  • No CAA records

Recommendations (2)

  • •Add MX records
  • •Add CAA records

Scan History

Loading history...