All checks use DNS-over-HTTPS — no direct connection to the target domain
What gets checked
25pts
SPF
Which servers can send email as your domain
20pts
DKIM
Cryptographic signature on outgoing messages
30pts
DMARC
Policy for SPF/DKIM failures + reporting
5pts
BIMI
Brand logo in Gmail/Apple Mail/Yahoo inboxes
5pts
MTA-STS
Force TLS on incoming SMTP connections
5pts
TLS-RPT
Reports when TLS fails on SMTP connections