Email Authentication Check

harvard.edu

This check reviews your domain's email authentication setup to help protect against spoofing and phishing.

All data shown is public and sourced from DNS.

Last checked about 21 hours ago

0 out of 110
Good

harvard.edu domain score

Your domain has basic email authentication in place. Consider strengthening your configuration for better protection.

Top Recommendation

+8

Upgrade DMARC policy to reject for stronger protection

DMARC improvement

harvard.edu has a DMARC quarantine policy, directing unauthenticated emails to spam. SPF is published with a soft fail policy (~all), flagging unauthorized senders without blocking them. A few improvements would strengthen harvard.edu's email authentication posture.

Curious how this compares? See the DMARC posture of the top 100 domains.

0

DMARC Check Results

37 / 50 points

Score Breakdown

DMARC record published
+10
Syntax valid
+5
Quarantine policy
+12 / 20
Aggregate reporting (rua) configured and verified
+10
Forensic reporting (ruf) not configured (optional)
0 / 5

DMARC check passed: properly configured

DMARC record is valid and configured correctly.

_dmarc.harvard.edu TXT Entry:

v=DMARC1; p=quarantine; sp=none; pct=100; adkim=r; aspf=r; rua=mailto:[email protected]

Policy (p)

quarantine

DKIM Alignment (adkim)

Relaxed (r)

SPF Alignment (aspf)

Relaxed (r)

Understanding alignment modes

DKIM Alignment (adkim)

Relaxed mode: The DKIM signature's domain can be a subdomain of the "From" header domain.

SPF Alignment (aspf)

Relaxed mode: The SPF "Return-Path" domain can be a subdomain of the "From" header domain.

Note: When alignment parameters are not specified, DMARC defaults to relaxed mode for both DKIM and SPF alignment.

Reporting (RUA/RUF)

Aggregate Reports

Configured
External Domain Verification

Verification successful

Forensic Reports

Not Configured

Add Our Monitoring System

You can add our monitoring system alongside your existing setup. DMARC supports multiple mailto: addresses, giving you additional visibility and backup reporting.

  • Automated DMARC report processing every 5 minutes
  • Track all sending sources and authentication results
  • Email alerts when your DNS records change
0

BIMI Check (default selector)

0 / 20 points

Score Breakdown

BIMI record published (optional)
0 / 5

No BIMI Record Found

Publish a TXT record at default._bimi.harvard.edu with v=BIMI1, logo URL (l=) and optional verified mark certificate (a=).

0

SPF Record Check Results

26 / 30 points

Score Breakdown

SPF record published
+10
Syntax valid
+5
Soft fail policy (~all)
+6 / 10
No configuration warnings
+5

SPF record is valid.

harvard.edu TXT SPF Entry:

v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~all

Syntax Check

OK

DNS Lookup Count

1 / 10 max

Void Lookups

0 / 2 max

Default Policy

~all

Soft fail: Mark emails from unauthorized servers as suspicious but don't reject

DNS Lookup Details

1
include:
%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email
Macro

Dynamic SPF macro - counts as 1 potential lookup when evaluated at delivery time

SPF Macro Variables:

%{i} = sender IP address, %{h} = HELO/EHLO domain, %{d} = current domain

This mechanism uses SPF macros that are expanded when an email is received. The actual domain queried depends on the sender's IP address and other connection details.

Lookup cost: 1
Included by harvard.edu
0

TLS Security

0 / 10 points

Score Breakdown

TLS-RPT record configured (optional)
0 / 5
MTA-STS policy configured (optional)
0 / 5

TLS-RPT (Reporting)

TLS-RPT Not Configured

Publish a TXT record at _smtp._tls.harvard.edu with v=TLSRPTv1 and reporting URI (rua=).

MTA-STS (Policy)

MTA-STS Not Configured

Publish a TXT record at _mta-sts.harvard.edu with v=STSv1 and policy ID (id=).

Protect inbound transport

You've checked your outbound authentication. But without MTA-STS and TLS-RPT, mail delivered to harvard.edu isn't protected against transport downgrade attacks. Receiver Shield helps you deploy, monitor, and safely enforce transport security.

Know when your DNS records change

The check you just ran shows your current configuration. But DNS records change, sometimes without you knowing. A well-meaning IT change, a third-party provider update, or an unauthorized modification can break your email delivery overnight.

Configuration Drift

IT changes that accidentally break authentication

Provider Updates

Third-party services changing their SPF includes

Unauthorized Changes

Attackers modifying records to send as you

DMARCTrust monitors your DNS records continuously. When something changes, you get an email alert with exactly what changed and why it matters. No more surprises when customers complain their emails bounced.

Email Security Configuration

How harvard.edu configures email authentication

DMARC Domain Policy
Configured
v=DMARC1; p=quarantine; sp=none; pct=100; adkim=r; aspf=r; rua=mailto:[email protected]
p=quarantine DKIM: relaxed SPF: relaxed Reports enabled
SPF Sender Authorization
Configured
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~all
~all 1 include
BIMI Brand Indicator
Not set
No BIMI record configured for this domain

Change History

Monitoring started April 06, 2026

Configuration changes will appear here when detected

Check Another Domain

Run a free email authentication check (DMARC, SPF, BIMI).

We will generate a shareable URL for your domain.

Try popular examples: google.com, amazon.com, booking.com

Explore other domains

Discover how other organizations configure their email authentication

Popular Domains

Frequently checked

Well-Configured

Reject policy + valid SPF

Same Policy

Also using quarantine

Showing domains checked by our users. All data is from public DNS records.

About This Checker

What we check

We analyze your domain's email authentication: DMARC policy and alignment, SPF record and includes, and BIMI logo and certificate status when present.

Why it matters

Healthy authentication improves delivery and blocks spoofing. Major inbox providers increasingly expect DMARC and aligned SPF/DKIM from senders.

Included features

  • DMARC syntax, policy, and reporting validation
  • SPF record evaluation and include analysis
  • DKIM/SPF alignment interpretation
  • BIMI record and VMC detection
  • Clear setup and remediation guidance

Monitor your email authentication 24/7

This check shows a snapshot. With DMARCTrust, you get continuous monitoring of your DMARC reports and DNS records, with instant alerts when something changes.