All data shown is public and sourced from DNS.
Last checked less than a minute ago
Your domain has strong email authentication. A few improvements can get you to a perfect score.
Upgrade to -all (hard fail) for maximum protection
SPF improvement
wellsfargo.com enforces a strict DMARC reject policy, instructing receivers to block unauthenticated emails. SPF is published with a soft fail policy (~all), flagging unauthorized senders without blocking them. Overall, wellsfargo.com has solid email authentication with room for minor improvements.
50 / 50 points
DMARC record is valid and configured correctly.
v=DMARC1; p=reject; fo=1; rua=mailto:[email protected],mailto:[email protected]; ruf=mailto:[email protected],mailto:[email protected];
Policy (p)
reject
DKIM Alignment (adkim)
Relaxed (default)
SPF Alignment (aspf)
Relaxed (default)
Verification successful
Verification successful
Verification successful
Verification successful
You can add our monitoring system alongside your existing setup. DMARC supports multiple mailto: addresses, giving you additional visibility and backup reporting.
20 / 20 points
BIMI Record Found and Looks Good
v=BIMI1;l=https://vmc.digicert.com/b708cb37-d48f-49f9-b2b0-31d535685a66.svg;a=https://vmc.digicert.com/b708cb37-d48f-49f9-b2b0-31d535685a66.pem
https://vmc.digicert.com/b708cb37-d48f-49f9-b2b0-31d535685a66.svg
image/svg+xml
Note: We do not parse SVG content for safety.
https://vmc.digicert.com/b708cb37-d48f-49f9-b2b0-31d535685a66.pem
Valid PEM detected
26 / 30 points
SPF record is valid.
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
Syntax Check
OK
DNS Lookup Count
1 / 10 max
Void Lookups
0 / 2 max
Soft fail: Mark emails from unauthorized servers as suspicious but don't reject
Dynamic SPF macro - counts as 1 potential lookup when evaluated at delivery time
SPF Macro Variables:
%{ir} = reversed sender IP address, %{v} = IP version (in-addr/ip6), %{d} = current domain
This mechanism uses SPF macros that are expanded when an email is received. The actual domain queried depends on the sender's IP address and other connection details.
wellsfargo.com
0 / 10 points
TLS-RPT Not Configured
Publish a TXT record at _smtp._tls.wellsfargo.com with v=TLSRPTv1 and reporting URI (rua=).
MTA-STS Not Configured
Publish a TXT record at _mta-sts.wellsfargo.com with v=STSv1 and policy ID (id=).
The check you just ran shows your current configuration. But DNS records change, sometimes without you knowing. A well-meaning IT change, a third-party provider update, or an unauthorized modification can break your email delivery overnight.
Configuration Drift
IT changes that accidentally break authentication
Provider Updates
Third-party services changing their SPF includes
Unauthorized Changes
Attackers modifying records to send as you
DMARCTrust monitors your DNS records continuously. When something changes, you get an email alert with exactly what changed and why it matters. No more surprises when customers complain their emails bounced.
Run a free email authentication check (DMARC, SPF, BIMI).
We will generate a shareable URL for your domain.
Try popular examples: google.com, amazon.com, booking.com
Discover how other organizations configure their email authentication
Frequently checked
Reject policy + valid SPF
Also using reject
Showing domains checked by our users. All data is from public DNS records.
We analyze your domain's email authentication: DMARC policy and alignment, SPF record and includes, and BIMI logo and certificate status when present.
Healthy authentication improves delivery and blocks spoofing. Major inbox providers increasingly expect DMARC and aligned SPF/DKIM from senders.
This check shows a snapshot. With DMARCTrust, you get continuous monitoring of your DMARC reports and DNS records, with instant alerts when something changes.
We use cookies to enhance your experience, analyze site traffic, and for marketing purposes. You can choose which cookies to allow. Learn more in our Cookie Policy.
Manage your cookie preferences below. Essential cookies are always active as they are required for the website to function.
Required for the website to function. Cannot be disabled.
Help us understand how visitors interact with our website.
Used to measure advertising effectiveness and show relevant ads.
Learn more about how we use cookies in our Cookie Policy.