Email Authentication Check

antin.co.uk

This gap analysis verifies compliance with email authentication standards to protect against spoofing and phishing.

All data displayed is public and provided by the DNS system.

Last checked 7 minutes ago

0 out of 110
Good

Domain Health Score

Your domain has strong email authentication. A few improvements can get you to a perfect score.

Top Recommendation

+16

Upgrade DMARC policy to quarantine or reject for stronger protection

DMARC improvement

0

DMARC Check Results

34 / 50 points

Score Breakdown

DMARC record published
+10
Syntax valid
+5
None policy (monitoring only)
+4 / 20
Aggregate reporting (rua) configured and verified
+10
Forensic reporting (ruf) configured
+5

DMARC check passed: properly configured

DMARC record is valid and configured correctly.

_dmarc.antin.co.uk TXT Entry:

v=DMARC1; p=none; pct=100; rua=mailto:[email protected],mailto:[email protected]; ruf=mailto:[email protected]

Policy (p)

none

DKIM Alignment (adkim)

Relaxed (default)

SPF Alignment (aspf)

Relaxed (default)

Reporting (RUA/RUF)

Aggregate Reports

Configured
External Domain Verification

Verification successful

Verification successful

Forensic Reports

Configured
External Domain Verification

Verification successful

0

BIMI Check (default selector)

15 / 20 points

Score Breakdown

BIMI record published
+5
BIMI record valid
+5
Logo URL accessible and valid SVG
+5
No VMC certificate configured (optional)
0 / 5

BIMI Record Found and Looks Good

Current BIMI Entry:

v=BIMI1; l=https://static1.squarespace.com/static/5a71ce89cf81e0a8f80b8ce5/t/69a58c6f21f9693ed8f7aa94/1772457071570/ANTIN-BIMI.svg

Mark Certificate

No certificate URL provided (a=). Optional when using self-asserted logos.

0

SPF Record Check Results

30 / 30 points

Score Breakdown

SPF record published
+10
Syntax valid
+5
Hard fail policy (-all)
+10
No configuration warnings
+5

SPF record is valid.

antin.co.uk TXT SPF Entry:

v=spf1 include:spf.protection.outlook.com -all

Syntax Check

OK

DNS Lookup Count

1 / 10 max

Void Lookups

0 / 2 max

Default Policy

-all

Fail: Reject emails from unauthorized servers (recommended for production)

All Authorized IP Addresses

Grouped by DNS record source (includes and sub-includes)

include:spf.protection.outlook.com | Microsoft 365
40.92.0.0/15
40.107.0.0/16
52.100.0.0/15
52.102.0.0/16
52.103.0.0/17
104.47.0.0/17
2a01:111:f400::/48
2a01:111:f403::/49
2a01:111:f403:8000::/51
2a01:111:f403:c000::/51
2a01:111:f403:f000::/52

DNS Lookup Details

1
include:
spf.protection.outlook.com | Microsoft 365
Valid

SPF record found

Lookup cost: 0
Included by antin.co.uk

TXT Record

v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all

Processed recursively per RFC 7208

0

TLS Security

5 / 10 points

Score Breakdown

TLS-RPT record configured
+5
MTA-STS policy configured (optional)
0 / 5

TLS-RPT (Reporting)

TLS-RPT Reporting Configured

Current TLS-RPT Entry:

v=TLSRPTv1; rua=mailto:[email protected]

Reporting URIs:

MTA-STS (Policy)

MTA-STS Not Configured

Publish a TXT record at _mta-sts.antin.co.uk with v=STSv1 and policy ID (id=).

Know when your DNS records change

The check you just ran shows your current configuration. But DNS records change, sometimes without you knowing. A well-meaning IT change, a third-party provider update, or an unauthorized modification can break your email delivery overnight.

Configuration Drift

IT changes that accidentally break authentication

Provider Updates

Third-party services changing their SPF includes

Unauthorized Changes

Attackers modifying records to send as you

DMARCTrust monitors your DNS records continuously. When something changes, you get an email alert with exactly what changed and why it matters. No more surprises when customers complain their emails bounced.

Check Another Domain

Run a free email authentication check (DMARC, SPF, BIMI).

We will generate a shareable URL for your domain.

Try popular examples: google.com, amazon.com, booking.com

Explore other domains

Discover how other organizations configure their email authentication

Popular Domains

Frequently checked

Well-Configured

Reject policy + valid SPF

Same Policy

Also using none

Showing domains checked by our users. All data is from public DNS records.

About This Checker

What we check

We analyze your domain's email authentication: DMARC policy and alignment, SPF record and includes, and BIMI logo/CV when present.

Why it matters

Healthy authentication improves delivery and blocks spoofing. Major inbox providers increasingly require DMARC and robust SPF/DKIM practices for senders.

Included features

  • DMARC syntax, policy, and reporting validation
  • SPF record evaluation and include analysis
  • DKIM/SPF alignment interpretation
  • BIMI record and VMC detection
  • Clear setup and remediation guidance

Related Tools

Monitor your email authentication 24/7

This check shows a snapshot. With DMARCTrust, you get continuous monitoring of your DMARC reports and DNS records, with instant alerts when something changes.