Skip to content

Domain email security check

The Denetta domain check is a free preliminary check that measures a domain’s email security from public DNS records only: it evaluates SPF, DKIM, DMARC, MTA-STS, TLS-RPT, DNSSEC, CAA, DANE, BIMI and name server redundancy with 21 checks and gives a 0-100 domain DNS score. None of your domain’s servers is contacted, and the domain you check is not stored in plain text.

Privacy and data handling — The domain you check is not stored in plain text; your IP address is not written to the database.

What does the preliminary check look at?

The checks below are the rules of Denetta’s full domain audit themselves; the preliminary check runs only the 21 checks that can be measured with DNS alone. The list is generated from the rule repository.

CodeCheckSeverity
MAIL-001No SPF recordHigh
MAIL-002SPF record is invalid (permerror): multiple records, syntax error, loop or void-lookup limitHigh
MAIL-003SPF record allows everyone (+all)Critical
MAIL-004SPF does not reject spoofed senders (?all, no all, or ~all without DMARC enforcement)Medium
MAIL-005SPF exceeds the 10 DNS lookup limitHigh
MAIL-006No DMARC recordHigh
MAIL-007DMARC policy only monitors (p=none)Medium
MAIL-008DMARC policy applies to only part of the mail (pct<100)Low
MAIL-009No DMARC report address (rua)Low
MAIL-010No DKIM key publishedHigh
MAIL-011DKIM key shorter than 2048 bitsMedium
MAIL-014MTA-STS missing or not enforcedLow
MAIL-015TLS-RPT reporting not configuredInfo
MAIL-023DNSSEC not enabledInfo
MAIL-024No CAA recordInfo
MAIL-025Name servers are not redundant (single server or all in the same /24)Medium
MAIL-026DKIM key in test mode (t=y)Medium
MAIL-028DANE: TLSA record is not validated by DNSSECLow
MAIL-029DANE (TLSA) not published although DNSSEC is readyInfo
MAIL-030No BIMI record (DMARC enforced, a logo could be shown)Info
MAIL-031BIMI record exists but the logo will not be shownLow

What does it not look at?

These checks require connecting to the domain’s servers: a STARTTLS handshake with the MX server, a TLS connection to the web server and a domain registration lookup. They are not run in the preliminary check, do not affect the score and are not counted as “unknown” either. They run in the full audit, with the domain owner’s signed written consent.

CodeCheckSeverity
MAIL-012MX server does not offer encrypted transport (STARTTLS)High
MAIL-013MX certificate invalid: expired, name mismatch or chain cannot be verifiedHigh
MAIL-016Website certificate has expiredCritical
MAIL-017Certificate expires within 14 daysHigh
MAIL-018Certificate expires within 30 daysMedium
MAIL-019Web server accepts legacy TLS versions (1.0/1.1)Medium
MAIL-020No HSTS on the websiteLow
MAIL-021Domain registration expires within 30 daysHigh
MAIL-022Domain registration has expiredCritical
MAIL-027DANE: MX certificate does not match the TLSA recordHigh

How is it measured?

Only DNS queries are made; they go to the Cloudflare (1.1.1.1) and Google (8.8.8.8) open resolvers. Denetta does not connect to your domain’s MX, web or name servers, sends no email and scans no ports.

The score is calculated with the full audit’s weighting model from these rules only, so it is not the same as your full audit score and is never written to any company’s score. If any of the SPF, DMARC or MX records cannot be read, no score is given and the result is “not measurable”. A record that cannot be read never counts as “passed”; it is shown separately as “unknown”.

The result is a summary: the score, the three most important findings and the severity distribution. Remediation text and evidence values come with the full audit, written for your DNS provider. Only a registered domain (e.g. example.com) is accepted; subdomains are not.

Questions about the domain check

Is the domain check free?

Yes. No sign-up or email address is needed. A Cloudflare Turnstile verification protects against automated abuse, and there is an hourly and daily query limit per IP address.

Is the domain I check stored?

Not in plain text, and it is not written to access logs; the domain in a shared link is only a URL fragment that stays in your browser and never reaches the server. The short-lived result cache and the per-period aggregate statistics are kept under a keyed digest of the domain, not the domain itself; when a period closes, the rows are deleted and the key is destroyed. Published statistics are totals only.

Is my IP address recorded?

It is not written to the database; the rate limit is kept in memory only. The server’s access logs are kept for at most 7 days with IP addresses masked.

Why don’t you connect to my servers?

Because every check that connects requires the domain owner’s signed and stamped written consent. Since anyone can run the preliminary check for any domain, it only looks at public DNS records.

What does “unknown” mean?

The DNS query timed out or the name server returned an error: we could not look. This does not mean “no record” and is not counted as “passed”; the score is calculated without those checks and their number is shown separately.

Why is the score different from my full audit score?

The preliminary check runs only the rules that can be measured with DNS; checks such as MX and web certificates, STARTTLS and domain registration do not count. The score is a preliminary indicator; it is never written to the Infrastructure Health Score or to any company record.

Why are subdomains not accepted?

Email records such as SPF, DMARC and MX are evaluated at the registered domain level, so the preliminary check accepts only a registered domain (e.g. example.com, example.com.tr).

Request a meeting for a full email audit.

The full audit also measures MX and web certificates, STARTTLS, DANE matching and domain registration expiry, writes remediation text for your DNS provider for every finding and monitors your domains every day.