IntoDNS.ai
ScanToolsCompareGuidesBlogPricingAPIAbout
Sign inStart your scan
IntoDNS.ai

Deterministic DNS and email security analysis with AI-assisted explanations where available. Built for developers, sysadmins and security-conscious teams.

Email testTool libraryAPI access

Product

  • Free scan
  • Free scanner
  • Tools
  • Pricing
  • API docs
  • Developers
  • MCP server
  • Security badge

Checks

  • SPF
  • DMARC
  • DKIM
  • DNSSEC
  • Blacklists
  • NIS2 readiness
  • Sender requirements
  • Email test
  • Diagnose email

Resources

  • Learn center
  • Blog
  • AI answers
  • Domain Security Reports
  • Methodology
  • Email security 2026
  • Compare tools
  • Verified domains

Company

  • About
  • Contact
  • Changelog
  • Privacy
  • Terms

© 2026 IntoDNS.ai. All rights reserved.

Deep scans via Internet.nlManaged hosting by CobytesXGitHubRSS
Back to home

shodan.io

DNS & Email Security Report

Google Public DNS

Overall Security Score

Based on DNS configuration, email security, and security checks

C
76%
Average

Adequate security, improvements recommended

dns
100%
dnssec
100%
ipv6
100%
email
58%
security
44%

Next best checks

The quick scan stays fast. Run deeper checks for mail transport, SPF complexity, BIMI readiness, or sender compliance.

NIS2 Article 21.2 readiness

Map this scan onto the ten NIS2 Article 21.2 measures and get a 0-100 readiness score with per-measure detail.

Evidence snapshot

Create a fixed Markdown report with DNS, mail, web, blacklist, sender, citation, timestamp, and hash evidence.

SMTP STARTTLS certificate

Live MX handshake, STARTTLS support, certificate trust, hostname match, and FCrDNS.

SPF lookup graph

See every include and redirect that counts toward the 10-lookup SPF limit.

BIMI logo and VMC/CMC

Validate the BIMI TXT record, hosted SVG logo, and mark-certificate URL before spending money.

FCrDNS / PTR

Check reverse DNS and forward confirmation for every mail-server IP in clustered or round-robin setups.

Sender requirements

Check Google/Yahoo/Microsoft sender expectations, blacklist posture, and authentication gaps.

Keep this domain on watch

Weekly updates and alerts keep DNS or mail changes from going unnoticed.

Recommendations (9)

Improve security
  • email
    DMARC policy quarantine or better
    DMARC policy: none. Set p=quarantine or p=reject
    -10 pts
  • email
    MX domains use DNSSEC
    0/1 MX domain(s) have DNSSEC. Ask your mail provider to enable DNSSEC
    -10 pts
  • email
    MX DNSSEC validation OK
    DNSSEC not enabled for MX domains
    -10 pts
  • security
    CAA records present
    No CAA records. Add CAA record to specify allowed certificate authorities
    -10 pts
  • security
    HSTS enabled
    No HSTS header. Add Strict-Transport-Security header with max-age of at least 31536000 (1 year)
    -15 pts
  • security
    X-Frame-Options header
    No X-Frame-Options header. Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
    -10 pts
  • security
    X-Content-Type-Options header
    No X-Content-Type-Options header. Add X-Content-Type-Options: nosniff to prevent MIME sniffing
    -10 pts
  • security
    Content-Security-Policy header
    No Content-Security-Policy header. Add CSP to prevent XSS and other injection attacks
    -15 pts
  • security
    Referrer-Policy header
    No Referrer-Policy header. Add Referrer-Policy: strict-origin-when-cross-origin
    -10 pts

Optional Features (11)

Nice to have
  • email
    DMARC policy reject
    DMARC policy: none. Set p=reject for maximum protection
    -20 pts
  • email
    BIMI record present
    No BIMI record. Add TXT at default._bimi with logo URL (requires DMARC p=quarantine+)
    -5 pts
  • email
    BIMI configuration valid
    No BIMI configured
    -5 pts
  • email
    MTA-STS record present
    No MTA-STS. Add TXT at _mta-sts and host policy at /.well-known/mta-sts.txt
    -5 pts
  • email
    MTA-STS policy enforced
    MTA-STS not configured
    -10 pts
  • security
    CAA policy strict
    CAA not strict. Add CAA 0 issue "letsencrypt.org" (or your CA) to restrict issuance
    -10 pts
  • security
    TLSA records (DANE)
    No TLSA/DANE records. Add TLSA at _25._tcp.mail for DANE email encryption
    -20 pts
  • security
    DANE configuration valid
    No DANE configured
    -15 pts
  • security
    HSTS max-age >= 1 year
    HSTS not enabled
    -10 pts
  • security
    security.txt present
    No security.txt. Create /.well-known/security.txt with Contact and Expires fields (RFC 9116)
    -5 pts
  • security
    security.txt valid
    No security.txt configured
    -5 pts

Passed checks (34)

  • A record present
  • AAAA record present
  • MX records present
  • NS records present
  • SOA record present
  • Multiple nameservers
  • MX servers have PTR records
  • MX servers have FCrDNS
  • DNSSEC signed
  • DNSSEC validation OK
  • NSEC3 RFC 9276 compliant
  • RRSIG signatures valid
  • Modern DNSSEC algorithm
  • DS digest algorithm modern
  • DNSKEY algorithm secure
  • RRSIG TTL safe
  • Chain of trust complete
  • Website reachable via IPv6
  • Mail servers publish IPv6
  • Nameservers reachable via IPv6
  • SPF record present
  • SPF syntax valid
  • SPF policy strict (-all)
  • DMARC record present
  • MX records valid
  • Mail servers not blacklisted
  • No critical blacklist listings
  • No sensitive info in TXT
  • HTTPS available
  • Valid certificate
  • HTTP redirects to HTTPS
  • HTTP/3 (QUIC) supported
  • QUIC UDP reachable
  • HTTPS DNS record (SVCB)
Computing NIS2 readiness…

Issues (2)

  • DMARC policy too lenient
  • No CAA records

Recommendations (2)

  • •Strengthen DMARC policy
  • •Add CAA records

Scan History

Loading history...