All data shown is public and sourced from DNS.
Last checked about 1 hour ago
drosafrica.org domain score
Your domain has basic email authentication in place. Consider strengthening your configuration for better protection.
Top Recommendation
Upgrade to -all (hard fail) for maximum protection
SPF improvement
drosafrica.org enforces a strict DMARC reject policy, instructing receivers to block unauthenticated emails. SPF is published with a soft fail policy (~all), flagging unauthorized senders without blocking them. A few improvements would strengthen drosafrica.org's email authentication posture.
DMARC Check Results
45 / 50 points
Score Breakdown
DMARC check passed: properly configured
DMARC record is valid and configured correctly.
_dmarc.drosafrica.org TXT Entry:
v=DMARC1; p=reject; rua=mailto:[email protected]; pct=100; adkim=s; aspf=s
Policy (p)
reject
DKIM Alignment (adkim)
Strict (s)
SPF Alignment (aspf)
Strict (s)
Understanding alignment modes
DKIM Alignment (adkim)
Strict mode: The DKIM signature's domain must exactly match the "From" header domain.
SPF Alignment (aspf)
Strict mode: The SPF "Return-Path" domain must exactly match the "From" header domain.
Note: When alignment parameters are not specified, DMARC defaults to relaxed mode for both DKIM and SPF alignment.
Reporting (RUA/RUF)
Add Our Monitoring System
You can add our monitoring system alongside your existing setup. DMARC supports multiple mailto: addresses, giving you additional visibility and backup reporting.
- Automated DMARC report processing every 5 minutes
- Track all sending sources and authentication results
- Email alerts when your DNS records change
BIMI Check (default selector)
0 / 20 points
Score Breakdown
No BIMI Record Found
Publish a TXT record at default._bimi.drosafrica.org with v=BIMI1, logo URL (l=) and optional verified mark certificate (a=).
SPF Record Check Results
26 / 30 points
Score Breakdown
SPF record is valid.
drosafrica.org TXT SPF Entry:
v=spf1 include:dc-aa8e722993._spfm.drosafrica.org ~all
Syntax Check
OK
DNS Lookup Count
5 / 10 max
Root-level mechanisms requiring DNS queries: 1.
Void Lookups
0 / 2 max
Default Policy
~allSoft fail: Mark emails from unauthorized servers as suspicious but don't reject
All Authorized IP Addresses
Grouped by DNS record source (includes and sub-includes)
include:_spf.google.com | Google
include:spf-0.secureserver.net
This record also contains:
include:spf.protection.outlook.com | Microsoft 365
DNS Lookup Details
include:
dc-aa8e722993._spfm.drosafrica.org
SPF record found
drosafrica.org
TXT Record
v=spf1 include:_spf.google.com include:secureserver.net ~all
Processed recursively per RFC 7208
include:
_spf.google.com
| Google
SPF record found
dc-aa8e722993._spfm.drosafrica.org
TXT Record
v=spf1 ip4:74.125.0.0/16 ip4:209.85.128.0/17 ip6:2001:4860:4864::/56 ip6:2404:6800:4864::/56 ip6:2607:f8b0:4864::/56 ip6:2800:3f0:4864::/56 ip6:2a00:1450:4864::/56 ip6:2c0f:fb50:4864::/56 ~all
Processed recursively per RFC 7208
include:
secureserver.net
SPF record found
dc-aa8e722993._spfm.drosafrica.org
TXT Record
v=spf1 include:spf-0.secureserver.net -all
Processed recursively per RFC 7208
include:
spf-0.secureserver.net
SPF record found
secureserver.net
TXT Record
v=spf1 ip4:64.202.168.0/24 ip4:97.74.135.0/24 ip4:72.167.238.0/24 ip4:72.167.234.0/24 ip4:72.167.218.0/24 ip4:68.178.252.0/24 ip4:68.178.213.0/24 ip4:216.69.139.0/24 ip4:208.109.80.0/24 ip4:92.204.81.0/24 ip4:198.71.224.0/19 ip4:184.168.224.0/24 ip4:184.168.200.0/24 ip4:184.168.131.0/24 ip4:184.168.128.0/24 ip4:92.204.65.0/28 ip4:182.50.132.0/24 ip4:173.201.192.0/23 ip4:72.167.168.0/24 ip4:92.204.71.0/24 ip4:132.148.124.0/24 ip4:72.167.172.0/24 ip4:188.121.52.0/24 ip4:188.121.53.0/24 ip4:52.89.65.132 ip4:54.214.222.76 ip4:54.184.82.65 ip4:52.26.164.15 ip4:68.178.181.0/24 ip4:50.63.8.0/22 ip4:208.109.194.0/24 ip4:80.237.138.192/26 include:spf.protection.outlook.com -all
Processed recursively per RFC 7208
include:
spf.protection.outlook.com
| Microsoft 365
SPF record found
spf-0.secureserver.net
TXT Record
v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all
Processed recursively per RFC 7208
TLS Security
0 / 10 points
Score Breakdown
TLS-RPT (Reporting)
TLS-RPT Not Configured
Publish a TXT record at _smtp._tls.drosafrica.org with v=TLSRPTv1 and reporting URI (rua=).
MTA-STS (Policy)
MTA-STS Not Configured
Publish a TXT record at _mta-sts.drosafrica.org with v=STSv1 and policy ID (id=).
Protect inbound transport
You've checked your outbound authentication. But without MTA-STS and TLS-RPT, mail delivered to drosafrica.org isn't protected against transport downgrade attacks. Receiver Shield helps you deploy, monitor, and safely enforce transport security.
Know when your DNS records change
The check you just ran shows your current configuration. But DNS records change, sometimes without you knowing. A well-meaning IT change, a third-party provider update, or an unauthorized modification can break your email delivery overnight.
Configuration Drift
IT changes that accidentally break authentication
Provider Updates
Third-party services changing their SPF includes
Unauthorized Changes
Attackers modifying records to send as you
DMARCTrust monitors your DNS records continuously. When something changes, you get an email alert with exactly what changed and why it matters. No more surprises when customers complain their emails bounced.
Check Another Domain
Run a free email authentication check (DMARC, SPF, BIMI).
We will generate a shareable URL for your domain.
Try popular examples: google.com, amazon.com, booking.com
Explore other domains
Discover how other organizations configure their email authentication
Popular Domains
Frequently checked
Well-Configured
Reject policy + valid SPF
Same Policy
Also using reject
Showing domains checked by our users. All data is from public DNS records.
About This Checker
What we check
We analyze your domain's email authentication: DMARC policy and alignment, SPF record and includes, and BIMI logo and certificate status when present.
Why it matters
Healthy authentication improves delivery and blocks spoofing. Major inbox providers increasingly expect DMARC and aligned SPF/DKIM from senders.
Included features
- DMARC syntax, policy, and reporting validation
- SPF record evaluation and include analysis
- DKIM/SPF alignment interpretation
- BIMI record and VMC detection
- Clear setup and remediation guidance
Monitor your email authentication 24/7
This check shows a snapshot. With DMARCTrust, you get continuous monitoring of your DMARC reports and DNS records, with instant alerts when something changes.