Dependency Chains
DMARC Authentication Chain (SPF)
DMARC uses SPF to verify that emails come from authorized servers
SPF Record
SPF record found and configured
→
DMARC Policy
DMARC policy: reject
DMARC Authentication Chain (DKIM)
DMARC uses DKIM to verify that emails have not been tampered with
DKIM Signature
DKIM signature configured
→
DMARC Policy
DMARC policy: reject
Mail Server Identity: mx1.smtp.goog
PTR record proves mail server legitimacy
MX: mx1.smtp.goog
Mail server at 216.239.32.151
→
PTR Record
No PTR record
⚠️ Mail server mx1.smtp.goog (216.239.32.151) lacks a PTR record. Many receiving servers require matching forward and reverse DNS for spam prevention.
Mail Server Identity: mx2.smtp.goog
PTR record proves mail server legitimacy
MX: mx2.smtp.goog
Mail server at 216.239.34.151
→
PTR Record
No PTR record
⚠️ Mail server mx2.smtp.goog (216.239.34.151) lacks a PTR record. Many receiving servers require matching forward and reverse DNS for spam prevention.
Mail Server Identity: aspmx.l.google.com
PTR record proves mail server legitimacy
MX: aspmx.l.google.com
Mail server at 209.85.203.27
→
PTR Record
Reverse DNS: dh-in-f27.1e100.net
Mail Server Identity: alt1.aspmx.l.google.com
PTR record proves mail server legitimacy
MX: alt1.aspmx.l.google.com
Mail server at 173.194.76.27
→
PTR Record
Reverse DNS: ws-in-f27.1e100.net
Mail Server Identity: alt2.aspmx.l.google.com
PTR record proves mail server legitimacy
MX: alt2.aspmx.l.google.com
Mail server at 142.250.102.26
→
PTR Record
Reverse DNS: rb-in-f26.1e100.net
Mail Server Identity: mx3.smtp.goog
PTR record proves mail server legitimacy
MX: mx3.smtp.goog
Mail server at 216.239.36.151
→
PTR Record
No PTR record
⚠️ Mail server mx3.smtp.goog (216.239.36.151) lacks a PTR record. Many receiving servers require matching forward and reverse DNS for spam prevention.
Mail Server Identity: mx4.smtp.goog
PTR record proves mail server legitimacy
MX: mx4.smtp.goog
Mail server at 216.239.38.151
→
PTR Record
No PTR record
⚠️ Mail server mx4.smtp.goog (216.239.38.151) lacks a PTR record. Many receiving servers require matching forward and reverse DNS for spam prevention.
Mail Server Reputation: mx1.smtp.goog
RBL check ensures server is not blacklisted
MX: mx1.smtp.goog
Mail server at 216.239.32.151
→
RBL Status
Not blacklisted
Mail Server Reputation: mx2.smtp.goog
RBL check ensures server is not blacklisted
MX: mx2.smtp.goog
Mail server at 216.239.34.151
→
RBL Status
Not blacklisted
Mail Server Reputation: aspmx.l.google.com
RBL check ensures server is not blacklisted
MX: aspmx.l.google.com
Mail server at 209.85.203.27
→
RBL Status
Not blacklisted
Mail Server Reputation: alt1.aspmx.l.google.com
RBL check ensures server is not blacklisted
MX: alt1.aspmx.l.google.com
Mail server at 173.194.76.27
→
RBL Status
Not blacklisted
Mail Server Reputation: alt2.aspmx.l.google.com
RBL check ensures server is not blacklisted
MX: alt2.aspmx.l.google.com
Mail server at 142.250.102.26
→
RBL Status
Not blacklisted
Mail Server Reputation: mx3.smtp.goog
RBL check ensures server is not blacklisted
MX: mx3.smtp.goog
Mail server at 216.239.36.151
→
RBL Status
Not blacklisted
Mail Server Reputation: mx4.smtp.goog
RBL check ensures server is not blacklisted
MX: mx4.smtp.goog
Mail server at 216.239.38.151
→
RBL Status
Not blacklisted
Enforced Encryption Chain
MTA-STS enforces TLS encryption to prevent man-in-the-middle attacks
TLS Support
Mail servers support TLS encryption
→
MTA-STS Policy
MTA-STS not configured
⚠️ MTA-STS policy is missing. Even with TLS support, you lack the enforcement layer that prevents attackers from stripping encryption (downgrade attacks).
Brand Identity Chain
BIMI displays your logo in email clients, but requires DMARC enforcement
DMARC Enforcement
DMARC policy: reject
→
BIMI Record
BIMI not configured
⚠️ BIMI record is missing. Even with DMARC enforcement, you need to configure BIMI to display your brand logo in supported email clients.
TLS Monitoring Chain
TLS-RPT provides reports about TLS connection failures
TLS Support
Mail servers support TLS encryption
→
TLS-RPT Reporting
TLS-RPT not configured
⚠️ TLS-RPT is not configured. Without TLS reporting, you have no visibility into TLS connection failures that may be impacting email delivery.