Email security guides
Browse the complete SPF, DKIM, DMARC, MX and related email-authentication knowledge base.
Open the email security hub →SPF · DKIM · DMARC · MX
SecuTest reviews externally visible email authentication and routing controls to identify conditions associated with spoofing exposure, broken authentication, weak enforcement and mail configuration errors.
Email security knowledge hub
The email-security hub groups the SPF, DKIM, DMARC and MX guides generated from the same checks used in SecuTest reports.
Browse the complete SPF, DKIM, DMARC, MX and related email-authentication knowledge base.
Open the email security hub →Presence, syntax, authorization policy and DNS lookup behavior.
SPF presence guide →Selectors, public keys, syntax, key strength and signature-verification prerequisites.
DKIM public key guide →Presence, policy enforcement, percentage, subdomain policy and reporting.
DMARC enforcement guide →Why email authentication matters
Email authentication is distributed across DNS records, signing infrastructure and receiver policy. A single headline such as “DMARC present” does not tell you whether the full configuration is valid, enforced or operationally safe.
Check whether SPF exists, whether its syntax is valid, whether the terminal policy is meaningful and whether DNS lookup behavior creates operational risk.
SPF presence guide →Review discoverable selectors, public-key validity, key strength, CNAME chains and conditions that can prevent signature verification.
DKIM public key guide →Distinguish monitoring-only policy from quarantine or reject, and review percentage, subdomain policy and aggregate reporting configuration.
DMARC enforcement guide →Validate MX syntax and resolution and identify cases such as null MX where the published behavior should match the domain's actual mail intent.
MX resolution guide →Interpretation
SecuTest separates configuration presence from syntax, validation and enforcement. This matters because remediation depends on the actual failure mode.
Missing: the expected control is not publicly published.
Invalid: a record exists but may not be usable by receivers because of syntax, key or resolution errors.
Weak: a technically valid control may still provide limited protection, such as DMARC p=none or incomplete enforcement.
Operational: a stronger policy still needs to account for legitimate senders, third-party platforms and production constraints before changes are made.
Assessment workflow
Read the public SPF, DKIM, DMARC and MX-related signals available for the target domain.
Check syntax, resolution, policy semantics and other conditions that affect whether a control works as intended.
Separate configuration hygiene from findings that materially influence spoofing exposure or authentication reliability.
Use operational guidance to fix legitimate sender alignment before enforcing stronger policies.
Check the published controls
Start with the free scan, then use the detailed report and remediation guides when you need the complete evidence.
Run Free Scan