Remediation: cloudflare.com
Scan #778 · 14 Feb 2026, 05:48 UTC · Achievable posture: Secure
Provider Quick Guide
- Log in to dash.cloudflare.com and select your domain
- Go to DNS → Records
- Click Add Record
- Select the Type shown below (TXT, CNAME, MX, etc.)
- Paste the Name (host) and Content (value) from each card below
- Set Proxy status to DNS only (grey cloud) for email records
- Click Save
- Log in to dcc.godaddy.com
- Select your domain, then click DNS (or Manage DNS)
- Scroll to DNS Records and click Add New Record
- Select the Type shown below
- In Name, enter the host (use
@for the root domain) - In Value, paste the record value from the card below
- Click Save
- Log in to your DNS hosting provider's control panel
- Navigate to DNS Management or Zone Editor
- Add a new record with the type, host, and value shown in each card below
- For the host field, use
@if your provider requires it for the root domain - Save and allow up to 24–48 hours for propagation (usually much faster)
DNS Records to Add or Update
DKIM is only configured for third-party services, not your primary mail platform (Google Workspace). Enable DKIM signing in Google Workspace settings to cover all outbound mail. Note: large organizations may already have DKIM configured with custom or rotating selectors not discoverable through standard checks — try re-scanning with a custom DKIM selector, or verify in your Google Workspace admin console.
Publish an MTA-STS DNS record and host a policy file at https://mta-sts.cloudflare.com/.well-known/mta-sts.txt. This tells senders to require TLS when delivering mail to your domain.
TLS-RPT (TLS Reporting) sends you reports about TLS connection failures when other servers try to deliver mail to your domain. Helps diagnose MTA-STS and STARTTLS issues.
Done making changes?
After updating your DNS records, run a new scan to verify everything is correct. DNS changes typically propagate within minutes, but can take up to 48 hours.
Re-Scan cloudflare.com