Dependency Chains
DMARC Authentication Chain (SPF)
DMARC uses SPF to verify that emails come from authorized servers
SPF Record
SPF record missing
→
DMARC Policy
DMARC policy: quarantine
⚠️ SPF record is missing. DMARC relies on SPF to verify sender authorization. Without SPF, DMARC alignment will fail, reducing email deliverability and brand protection.
DMARC Authentication Chain (DKIM)
DMARC uses DKIM to verify that emails have not been tampered with
DKIM Signature
DKIM signature missing
→
DMARC Policy
DMARC policy: quarantine
⚠️ DKIM signature is missing. DMARC relies on DKIM to verify email integrity and prevent tampering. Without DKIM, DMARC alignment will fail for cryptographic verification.
Mail Server Identity: mxa.global.inbound.cf-emailsecurity.net
PTR record proves mail server legitimacy
MX: mxa.global.inbound.cf-emailsecurity.net
Mail server at 172.65.64.78
→
PTR Record
No PTR record
⚠️ Mail server mxa.global.inbound.cf-emailsecurity.net (172.65.64.78) lacks a PTR record. Many receiving servers require matching forward and reverse DNS for spam prevention.
Mail Server Identity: mxb.global.inbound.cf-emailsecurity.net
PTR record proves mail server legitimacy
MX: mxb.global.inbound.cf-emailsecurity.net
Mail server at 141.101.90.40
→
PTR Record
No PTR record
⚠️ Mail server mxb.global.inbound.cf-emailsecurity.net (141.101.90.40) lacks a PTR record. Many receiving servers require matching forward and reverse DNS for spam prevention.
Mail Server Reputation: mxa.global.inbound.cf-emailsecurity.net
RBL check ensures server is not blacklisted
MX: mxa.global.inbound.cf-emailsecurity.net
Mail server at 172.65.64.78
→
RBL Status
Not blacklisted
Mail Server Reputation: mxb.global.inbound.cf-emailsecurity.net
RBL check ensures server is not blacklisted
MX: mxb.global.inbound.cf-emailsecurity.net
Mail server at 141.101.90.40
→
RBL Status
Not blacklisted
Enforced Encryption Chain
MTA-STS enforces TLS encryption to prevent man-in-the-middle attacks
TLS Support
Mail servers support TLS encryption
→
MTA-STS Policy
MTA-STS not configured
⚠️ MTA-STS policy is missing. Even with TLS support, you lack the enforcement layer that prevents attackers from stripping encryption (downgrade attacks).
Brand Identity Chain
BIMI displays your logo in email clients, but requires DMARC enforcement
DMARC Enforcement
DMARC policy: quarantine
→
BIMI Record
BIMI not configured
⚠️ BIMI record is missing. Even with DMARC enforcement, you need to configure BIMI to display your brand logo in supported email clients.
TLS Monitoring Chain
TLS-RPT provides reports about TLS connection failures
TLS Support
Mail servers support TLS encryption
→
TLS-RPT Reporting
TLS-RPT not configured
⚠️ TLS-RPT is not configured. Without TLS reporting, you have no visibility into TLS connection failures that may be impacting email delivery.