Dependency Chains
DMARC Authentication Chain (SPF)
DMARC uses SPF to verify that emails come from authorized servers
SPF Record
SPF record found and configured
→
DMARC Policy
DMARC policy: reject
DMARC Authentication Chain (DKIM)
DMARC uses DKIM to verify that emails have not been tampered with
DKIM Signature
DKIM signature configured
→
DMARC Policy
DMARC policy: reject
Mail Server Identity: mx1.forwardemail.net
PTR record proves mail server legitimacy
MX: mx1.forwardemail.net
Mail server at 138.197.213.185
→
PTR Record
Reverse DNS: mx1.forwardemail.net
Mail Server Identity: mx2.forwardemail.net
PTR record proves mail server legitimacy
MX: mx2.forwardemail.net
Mail server at 121.127.44.59
→
PTR Record
Reverse DNS: mx2.forwardemail.net
Mail Server Reputation: mx1.forwardemail.net
RBL check ensures server is not blacklisted
MX: mx1.forwardemail.net
Mail server at 138.197.213.185
→
RBL Status
Not blacklisted
Mail Server Reputation: mx2.forwardemail.net
RBL check ensures server is not blacklisted
MX: mx2.forwardemail.net
Mail server at 121.127.44.59
→
RBL Status
Not blacklisted
Enforced Encryption Chain
MTA-STS enforces TLS encryption to prevent man-in-the-middle attacks
TLS Support
Mail servers support TLS encryption
→
MTA-STS Policy
Mode: enforce
Brand Identity Chain
BIMI displays your logo in email clients, but requires DMARC enforcement
DMARC Enforcement
DMARC policy: reject
→
BIMI Record
BIMI not configured
⚠️ BIMI record is missing. Even with DMARC enforcement, you need to configure BIMI to display your brand logo in supported email clients.
TLS Monitoring Chain
TLS-RPT provides reports about TLS connection failures
TLS Support
Mail servers support TLS encryption
→
TLS-RPT Reporting
TLS failure reporting configured