
What Requires Attention
The BIG Questions
Domain Overview
Technical Findings
Email Authentication
Mail Transport Security
DNS Security
Brand & Certificate Controls
AI Surface Scanner Scanned
Priority Actions 3 total Achievable: Hardened
DNSSEC is not enabled for this domain. DNSSEC provides cryptographic authentication of DNS responses, preventing cache poisoning and DNS spoofing attacks.
Your domain has DMARC reject — you qualify for BIMI, which displays your brand logo in receiving email clients that support it (Gmail, Apple Mail, Yahoo).
CAA records specify which Certificate Authorities may issue certificates for your domain, reducing the risk of unauthorized certificate issuance.
Appendix — Additional Resources
Full technical details including raw DNS records, DKIM public keys, IP/ASN mappings, resolver consensus evidence, and verification commands are available in the Engineer's DNS Intelligence Report.
Verify Report Integrity SHA-3-512 Has this report been tampered with? Verify below
Tamper-evident fingerprint binding this analysis to its data, domain, timestamp, and tool version.
08c333fce4e3e005fc2d182b897fbcac3ed47e739ed559a8f344f7ee4c541210fad830f9762b8a4b62666edf837c38532e235e93f4c9978c966f55ec3f4b27f8
Internet Archive — Permanent Record Wayback Machine
This analysis is permanently archived by the Internet Archive, providing independent third-party verification of DNS security posture at analysis time.
View Archived Snapshot