Dependency Chains
DMARC Authentication Chain (SPF)
DMARC uses SPF to verify that emails come from authorized servers
SPF Record
SPF record found and configured
→
DMARC Policy
DMARC policy: quarantine
DMARC Authentication Chain (DKIM)
DMARC uses DKIM to verify that emails have not been tampered with
DKIM Signature
DKIM signature configured
→
DMARC Policy
DMARC policy: quarantine
Mail Server Identity: mx2.pokerstars.com
PTR record proves mail server legitimacy
MX: mx2.pokerstars.com
Mail server at 3.255.61.172
→
PTR Record
Reverse DNS: ec2-3-255-61-172.eu-west-1.compute.amazonaws.com
Mail Server Reputation: mx2.pokerstars.com
RBL check ensures server is not blacklisted
MX: mx2.pokerstars.com
Mail server at 3.255.61.172
→
RBL Status
Not blacklisted
Enforced Encryption Chain
MTA-STS enforces TLS encryption to prevent man-in-the-middle attacks
TLS Support
Mail servers support TLS encryption
→
MTA-STS Policy
MTA-STS not configured
⚠️ MTA-STS policy is missing. Even with TLS support, you lack the enforcement layer that prevents attackers from stripping encryption (downgrade attacks).
Brand Identity Chain
BIMI displays your logo in email clients, but requires DMARC enforcement
DMARC Enforcement
DMARC policy: quarantine
→
BIMI Record
Brand logo configured
TLS Monitoring Chain
TLS-RPT provides reports about TLS connection failures
TLS Support
Mail servers support TLS encryption
→
TLS-RPT Reporting
TLS failure reporting configured