Dependency Chains
DMARC Authentication Chain (SPF)
DMARC uses SPF to verify that emails come from authorized servers
SPF Record
SPF record missing
→
DMARC Policy
DMARC policy missing
⚠️ SPF record is missing. DMARC relies on SPF to verify sender authorization. Without SPF, DMARC alignment will fail, reducing email deliverability and brand protection.
DMARC Authentication Chain (DKIM)
DMARC uses DKIM to verify that emails have not been tampered with
DKIM Signature
DKIM signature configured
→
DMARC Policy
DMARC policy missing
⚠️ DMARC policy is missing. Even with DKIM configured, you lack the policy layer that tells receiving servers what to do with authentication failures.
Mail Server Identity: aspmx.l.google.com
PTR record proves mail server legitimacy
MX: aspmx.l.google.com
Mail server at 74.125.193.26
→
PTR Record
Reverse DNS: di-in-f26.1e100.net
Mail Server Identity: alt1.aspmx.l.google.com
PTR record proves mail server legitimacy
MX: alt1.aspmx.l.google.com
Mail server at 173.194.76.26
→
PTR Record
Reverse DNS: ws-in-f26.1e100.net
Mail Server Identity: alt2.aspmx.l.google.com
PTR record proves mail server legitimacy
MX: alt2.aspmx.l.google.com
Mail server at 142.250.102.26
→
PTR Record
Reverse DNS: rb-in-f26.1e100.net
Mail Server Identity: aspmx2.googlemail.com
PTR record proves mail server legitimacy
MX: aspmx2.googlemail.com
Mail server at 173.194.76.26
→
PTR Record
Reverse DNS: ws-in-f26.1e100.net
Mail Server Identity: aspmx3.googlemail.com
PTR record proves mail server legitimacy
MX: aspmx3.googlemail.com
Mail server at 142.250.102.26
→
PTR Record
Reverse DNS: rb-in-f26.1e100.net
Mail Server Reputation: aspmx.l.google.com
RBL check ensures server is not blacklisted
MX: aspmx.l.google.com
Mail server at 74.125.193.26
→
RBL Status
Not blacklisted
Mail Server Reputation: alt1.aspmx.l.google.com
RBL check ensures server is not blacklisted
MX: alt1.aspmx.l.google.com
Mail server at 173.194.76.26
→
RBL Status
Not blacklisted
Mail Server Reputation: alt2.aspmx.l.google.com
RBL check ensures server is not blacklisted
MX: alt2.aspmx.l.google.com
Mail server at 142.250.102.26
→
RBL Status
Not blacklisted
Mail Server Reputation: aspmx2.googlemail.com
RBL check ensures server is not blacklisted
MX: aspmx2.googlemail.com
Mail server at 173.194.76.26
→
RBL Status
Not blacklisted
Mail Server Reputation: aspmx3.googlemail.com
RBL check ensures server is not blacklisted
MX: aspmx3.googlemail.com
Mail server at 142.250.102.26
→
RBL Status
Not blacklisted
Enforced Encryption Chain
MTA-STS enforces TLS encryption to prevent man-in-the-middle attacks
TLS Support
Mail servers support TLS encryption
→
MTA-STS Policy
MTA-STS not configured
⚠️ MTA-STS policy is missing. Even with TLS support, you lack the enforcement layer that prevents attackers from stripping encryption (downgrade attacks).
Brand Identity Chain
BIMI displays your logo in email clients, but requires DMARC enforcement
DMARC Enforcement
DMARC not enforced (p=none or missing)
→
BIMI Record
BIMI not configured
⚠️ DMARC is not enforced. BIMI requires a DMARC policy of "quarantine" or "reject" to prove you have strong email authentication. Without enforcement, email clients will not display your logo.
TLS Monitoring Chain
TLS-RPT provides reports about TLS connection failures
TLS Support
Mail servers support TLS encryption
→
TLS-RPT Reporting
TLS failure reporting configured