Dependency Chains
DMARC Authentication Chain (SPF)
DMARC uses SPF to verify that emails come from authorized servers
SPF Record
SPF record found and configured
→
DMARC Policy
DMARC policy: reject
DMARC Authentication Chain (DKIM)
DMARC uses DKIM to verify that emails have not been tampered with
DKIM Signature
DKIM signature missing
→
DMARC Policy
DMARC policy: reject
⚠️ DKIM signature is missing. DMARC relies on DKIM to verify email integrity and prevent tampering. Without DKIM, DMARC alignment will fail for cryptographic verification.
Mail Server Identity: mxz1.klarna.com
PTR record proves mail server legitimacy
MX: mxz1.klarna.com
Mail server at 52.30.236.203
→
PTR Record
Reverse DNS: ec2-52-30-236-203.eu-west-1.compute.amazonaws.com
Mail Server Identity: mxz2.klarna.com
PTR record proves mail server legitimacy
MX: mxz2.klarna.com
Mail server at 54.73.174.245
→
PTR Record
Reverse DNS: ec2-54-73-174-245.eu-west-1.compute.amazonaws.com
Mail Server Identity: mxz3.klarna.com
PTR record proves mail server legitimacy
MX: mxz3.klarna.com
Mail server at 3.73.181.240
→
PTR Record
Reverse DNS: ec2-3-73-181-240.eu-central-1.compute.amazonaws.com
Mail Server Identity: mxz4.klarna.com
PTR record proves mail server legitimacy
MX: mxz4.klarna.com
Mail server at 35.156.176.213
→
PTR Record
Reverse DNS: ec2-35-156-176-213.eu-central-1.compute.amazonaws.com
Mail Server Reputation: mxz1.klarna.com
RBL check ensures server is not blacklisted
MX: mxz1.klarna.com
Mail server at 52.30.236.203
→
RBL Status
Not blacklisted
Mail Server Reputation: mxz2.klarna.com
RBL check ensures server is not blacklisted
MX: mxz2.klarna.com
Mail server at 54.73.174.245
→
RBL Status
Not blacklisted
Mail Server Reputation: mxz3.klarna.com
RBL check ensures server is not blacklisted
MX: mxz3.klarna.com
Mail server at 3.73.181.240
→
RBL Status
Not blacklisted
Mail Server Reputation: mxz4.klarna.com
RBL check ensures server is not blacklisted
MX: mxz4.klarna.com
Mail server at 35.156.176.213
→
RBL Status
Not blacklisted
Enforced Encryption Chain
MTA-STS enforces TLS encryption to prevent man-in-the-middle attacks
TLS Support
TLS not verified or unsupported
→
MTA-STS Policy
MTA-STS not configured
⚠️ TLS support could not be verified. MTA-STS requires TLS to enforce encrypted connections. Without TLS, MTA-STS cannot function.
Brand Identity Chain
BIMI displays your logo in email clients, but requires DMARC enforcement
DMARC Enforcement
DMARC policy: reject
→
BIMI Record
Brand logo configured
TLS Monitoring Chain
TLS-RPT provides reports about TLS connection failures
TLS Support
TLS not verified or unsupported
→
TLS-RPT Reporting
TLS-RPT not configured
⚠️ TLS support could not be verified. TLS-RPT reports on TLS connection failures, but without TLS support, there's nothing to monitor. You need working TLS encryption before TLS-RPT can provide value.