Dependency Chains
DMARC Authentication Chain (SPF)
DMARC uses SPF to verify that emails come from authorized servers
SPF Record
SPF record found and configured
โ
DMARC Policy
DMARC policy: none
DMARC Authentication Chain (DKIM)
DMARC uses DKIM to verify that emails have not been tampered with
DKIM Signature
DKIM signature missing
โ
DMARC Policy
DMARC policy: none
โ ๏ธ DKIM signature is missing. DMARC relies on DKIM to verify email integrity and prevent tampering. Without DKIM, DMARC alignment will fail for cryptographic verification.
Mail Server Identity: usatoday-com.mail.protection.outlook.com
PTR record proves mail server legitimacy
MX: usatoday-com.mail.protection.outlook.com
Mail server at 52.101.10.14
โ
PTR Record
Reverse DNS: mail-bn6pr04cu00206.inbound.protection.outlook.com
Mail Server Reputation: usatoday-com.mail.protection.outlook.com
RBL check ensures server is not blacklisted
MX: usatoday-com.mail.protection.outlook.com
Mail server at 52.101.10.14
โ
RBL Status
Not blacklisted
Enforced Encryption Chain
MTA-STS enforces TLS encryption to prevent man-in-the-middle attacks
TLS Support
Mail servers support TLS encryption
โ
MTA-STS Policy
Mode:
Brand Identity Chain
BIMI displays your logo in email clients, but requires DMARC enforcement
DMARC Enforcement
DMARC not enforced (p=none or missing)
โ
BIMI Record
BIMI not configured
โ ๏ธ DMARC is not enforced. BIMI requires a DMARC policy of "quarantine" or "reject" to prove you have strong email authentication. Without enforcement, email clients will not display your logo.
TLS Monitoring Chain
TLS-RPT provides reports about TLS connection failures
TLS Support
Mail servers support TLS encryption
โ
TLS-RPT Reporting
TLS-RPT not configured
โ ๏ธ TLS-RPT is not configured. Without TLS reporting, you have no visibility into TLS connection failures that may be impacting email delivery.