Domain email security check
The Denetta domain check is a free preliminary check that measures a domain’s email security from public DNS records only: it evaluates SPF, DKIM, DMARC, MTA-STS, TLS-RPT, DNSSEC, CAA, DANE, BIMI and name server redundancy with 21 checks and gives a 0-100 domain DNS score. None of your domain’s servers is contacted, and the domain you check is not stored in plain text.
Privacy and data handling — The domain you check is not stored in plain text; your IP address is not written to the database.
What does the preliminary check look at?
The checks below are the rules of Denetta’s full domain audit themselves; the preliminary check runs only the 21 checks that can be measured with DNS alone. The list is generated from the rule repository.
| Code | Check | Severity |
|---|---|---|
MAIL-001 | No SPF record | High |
MAIL-002 | SPF record is invalid (permerror): multiple records, syntax error, loop or void-lookup limit | High |
MAIL-003 | SPF record allows everyone (+all) | Critical |
MAIL-004 | SPF does not reject spoofed senders (?all, no all, or ~all without DMARC enforcement) | Medium |
MAIL-005 | SPF exceeds the 10 DNS lookup limit | High |
MAIL-006 | No DMARC record | High |
MAIL-007 | DMARC policy only monitors (p=none) | Medium |
MAIL-008 | DMARC policy applies to only part of the mail (pct<100) | Low |
MAIL-009 | No DMARC report address (rua) | Low |
MAIL-010 | No DKIM key published | High |
MAIL-011 | DKIM key shorter than 2048 bits | Medium |
MAIL-014 | MTA-STS missing or not enforced | Low |
MAIL-015 | TLS-RPT reporting not configured | Info |
MAIL-023 | DNSSEC not enabled | Info |
MAIL-024 | No CAA record | Info |
MAIL-025 | Name servers are not redundant (single server or all in the same /24) | Medium |
MAIL-026 | DKIM key in test mode (t=y) | Medium |
MAIL-028 | DANE: TLSA record is not validated by DNSSEC | Low |
MAIL-029 | DANE (TLSA) not published although DNSSEC is ready | Info |
MAIL-030 | No BIMI record (DMARC enforced, a logo could be shown) | Info |
MAIL-031 | BIMI record exists but the logo will not be shown | Low |
What does it not look at?
These checks require connecting to the domain’s servers: a STARTTLS handshake with the MX server, a TLS connection to the web server and a domain registration lookup. They are not run in the preliminary check, do not affect the score and are not counted as “unknown” either. They run in the full audit, with the domain owner’s signed written consent.
| Code | Check | Severity |
|---|---|---|
MAIL-012 | MX server does not offer encrypted transport (STARTTLS) | High |
MAIL-013 | MX certificate invalid: expired, name mismatch or chain cannot be verified | High |
MAIL-016 | Website certificate has expired | Critical |
MAIL-017 | Certificate expires within 14 days | High |
MAIL-018 | Certificate expires within 30 days | Medium |
MAIL-019 | Web server accepts legacy TLS versions (1.0/1.1) | Medium |
MAIL-020 | No HSTS on the website | Low |
MAIL-021 | Domain registration expires within 30 days | High |
MAIL-022 | Domain registration has expired | Critical |
MAIL-027 | DANE: MX certificate does not match the TLSA record | High |
How is it measured?
Only DNS queries are made; they go to the Cloudflare (1.1.1.1) and Google (8.8.8.8) open resolvers. Denetta does not connect to your domain’s MX, web or name servers, sends no email and scans no ports.
The score is calculated with the full audit’s weighting model from these rules only, so it is not the same as your full audit score and is never written to any company’s score. If any of the SPF, DMARC or MX records cannot be read, no score is given and the result is “not measurable”. A record that cannot be read never counts as “passed”; it is shown separately as “unknown”.
The result is a summary: the score, the three most important findings and the severity distribution. Remediation text and evidence values come with the full audit, written for your DNS provider. Only a registered domain (e.g. example.com) is accepted; subdomains are not.
Questions about the domain check
Is the domain check free?
Yes. No sign-up or email address is needed. A Cloudflare Turnstile verification protects against automated abuse, and there is an hourly and daily query limit per IP address.
Is the domain I check stored?
Not in plain text, and it is not written to access logs; the domain in a shared link is only a URL fragment that stays in your browser and never reaches the server. The short-lived result cache and the per-period aggregate statistics are kept under a keyed digest of the domain, not the domain itself; when a period closes, the rows are deleted and the key is destroyed. Published statistics are totals only.
Is my IP address recorded?
It is not written to the database; the rate limit is kept in memory only. The server’s access logs are kept for at most 7 days with IP addresses masked.
Why don’t you connect to my servers?
Because every check that connects requires the domain owner’s signed and stamped written consent. Since anyone can run the preliminary check for any domain, it only looks at public DNS records.
What does “unknown” mean?
The DNS query timed out or the name server returned an error: we could not look. This does not mean “no record” and is not counted as “passed”; the score is calculated without those checks and their number is shown separately.
Why is the score different from my full audit score?
The preliminary check runs only the rules that can be measured with DNS; checks such as MX and web certificates, STARTTLS and domain registration do not count. The score is a preliminary indicator; it is never written to the Infrastructure Health Score or to any company record.
Why are subdomains not accepted?
Email records such as SPF, DMARC and MX are evaluated at the registered domain level, so the preliminary check accepts only a registered domain (e.g. example.com, example.com.tr).
Request a meeting for a full email audit.
The full audit also measures MX and web certificates, STARTTLS, DANE matching and domain registration expiry, writes remediation text for your DNS provider for every finding and monitors your domains every day.