SPF · DKIM · DMARC · MX
Email Security Guides
Review email authentication, routing and policy findings by control family. Each guide explains the observed condition, threat model, remediation steps and external verification workflow.
Scan a domain Explore Email Security AssessmentEmail security
Find the remediation guide for your finding
Use the check name from a SecuTest report to open the matching operational guide.
Email Security AssessmentCheck SPF, DKIM, DMARC and MX across a real domain, then use these guides to remediate the exact findings. Run the related assessment →
Email securityDKIM CNAME chainA broken, looping, or excessively long DKIM CNAME chain can prevent receivers from retrieving the signing key.Open remediation guide →Email securityDKIM public key presenceA selector record without an active public key cannot validate signatures and may represent an incomplete or unintended revocation.Open remediation guide →Email securityDKIM public key strengthA weak DKIM key may not provide adequate resistance to key recovery or signature forgery over its operational lifetime.Open remediation guide →Email securityDKIM record syntaxMalformed DKIM tags can make a published key unusable and cause signature verification failures.Open remediation guide →Email securityDKIM testing flagLeaving `t=y` enabled in production can signal that verification failures should be treated less strictly than intended.Open remediation guide →Email securityDMARC aggregate reportingWithout aggregate reporting, the organization loses visibility into legitimate authentication failures and unauthorized use of its domains.Open remediation guide →Email securityDMARC enforcement percentageA `pct` value below 100 intentionally leaves part of failing mail outside the requested enforcement policy.Open remediation guide →Email securityDMARC enforcement policyA monitoring-only `p=none` policy records abuse but does not ask receivers to quarantine or reject unauthenticated direct-domain mail.Open remediation guide →Email securityDMARC record presenceWithout DMARC, the visible From domain has no published alignment and handling policy, increasing exposure to direct-domain spoofing and phishing.Open remediation guide →Email securityDMARC subdomain policyA weaker `sp` policy can leave unused or forgotten subdomains available for spoofing even when the organizational domain enforces DMARC.Open remediation guide →Email securityDuplicate DKIM recordsMultiple conflicting DKIM records for one selector can make key retrieval ambiguous and cause signature verification failures.Open remediation guide →Email securityNull MX configurationAn invalid or mixed Null MX declaration creates contradictory mail-routing instructions and can cause delivery failures or unintended fallback behavior.Open remediation guide →Email securityResolvable DKIM selectorA configured DKIM selector that does not resolve prevents receivers from retrieving the public key needed to verify signatures.Open remediation guide →Email securityResolvable MX targetsAn MX target that does not resolve cannot receive mail and may indicate stale infrastructure or, in some provider-specific cases, a takeover opportunity.Open remediation guide →Email securitySPF DNS lookup limitExceeding SPF's ten DNS-lookup limit causes a permanent error, breaking authentication for messages that reach the excessive path.Open remediation guide →Email securitySPF PTR mechanismThe deprecated SPF `ptr` mechanism is slow, fragile, and can authorize hosts based on reverse-DNS relationships that are difficult to control and audit.Open remediation guide →Email securitySPF all mechanism policyA missing, neutral, soft, duplicated, or permissive `all` mechanism can authorize unintended senders or leave spoofing decisions weak.Open remediation guide →Email securitySPF include and redirect recursionBroken, circular, missing, or excessively deep SPF dependencies can produce permanent errors and invalidate sender authorization.Open remediation guide →Email securitySPF record presenceWithout SPF, receivers have no domain-published list of authorized envelope senders, increasing exposure to email spoofing and phishing.Open remediation guide →Email securitySingle DMARC recordMultiple DMARC records make the policy invalid, so receivers cannot reliably enforce the intended anti-spoofing controls.Open remediation guide →Email securitySingle SPF recordPublishing multiple SPF records causes a permanent SPF error, disabling reliable sender authorization and potentially harming delivery.Open remediation guide →Email securityValid DKIM public keyAn invalid DKIM public key cannot verify message signatures and can break DMARC for senders that rely on DKIM alignment.Open remediation guide →Email securityValid DMARC syntaxInvalid DMARC tags, values, ordering, or reporting URIs can invalidate the policy and prevent reliable enforcement or reporting.Open remediation guide →Email securityValid MX record syntaxMalformed MX records can make inbound mail delivery unreliable or impossible and may send mail systems down unintended fallback paths.Open remediation guide →Email securityValid SPF syntaxInvalid SPF mechanisms, modifiers, qualifiers, or ordering can produce a permanent error and make the policy unusable.Open remediation guide →