Dependency Chains
DMARC Authentication Chain (SPF)
DMARC uses SPF to verify that emails come from authorized servers
SPF Record
SPF record found and configured
→
DMARC Policy
DMARC policy: none
DMARC Authentication Chain (DKIM)
DMARC uses DKIM to verify that emails have not been tampered with
DKIM Signature
DKIM signature missing
→
DMARC Policy
DMARC policy: none
⚠️ DKIM signature is missing. DMARC relies on DKIM to verify email integrity and prevent tampering. Without DKIM, DMARC alignment will fail for cryptographic verification.
Mail Server Identity: tvg-com.mail.protection.outlook.com
PTR record proves mail server legitimacy
MX: tvg-com.mail.protection.outlook.com
Mail server at 52.101.40.6
→
PTR Record
Reverse DNS: mail-cy1pr03cu00106.inbound.protection.outlook.com
Mail Server Reputation: tvg-com.mail.protection.outlook.com
RBL check ensures server is not blacklisted
MX: tvg-com.mail.protection.outlook.com
Mail server at 52.101.40.6
→
RBL Status
Not blacklisted
Enforced Encryption Chain
MTA-STS enforces TLS encryption to prevent man-in-the-middle attacks
TLS Support
Mail servers support TLS encryption
→
MTA-STS Policy
MTA-STS not configured
⚠️ MTA-STS policy is missing. Even with TLS support, you lack the enforcement layer that prevents attackers from stripping encryption (downgrade attacks).
Brand Identity Chain
BIMI displays your logo in email clients, but requires DMARC enforcement
DMARC Enforcement
DMARC not enforced (p=none or missing)
→
BIMI Record
BIMI not configured
⚠️ DMARC is not enforced. BIMI requires a DMARC policy of "quarantine" or "reject" to prove you have strong email authentication. Without enforcement, email clients will not display your logo.
TLS Monitoring Chain
TLS-RPT provides reports about TLS connection failures
TLS Support
Mail servers support TLS encryption
→
TLS-RPT Reporting
TLS-RPT not configured
⚠️ TLS-RPT is not configured. Without TLS reporting, you have no visibility into TLS connection failures that may be impacting email delivery.