5 nameservers
OKThe domain delegates to these nameservers. Two or more, on separate infrastructure, is the usual minimum for resilience.
Report
Every check passed. Records can still change without warning — that is what monitoring is for.
Delegation
The domain delegates to these nameservers. Two or more, on separate infrastructure, is the usual minimum for resilience.
Registration
That is 2360 days away.
The domain is about 17 years old. Age is one of the weaker signals receivers use when deciding whether new mail from a domain is trustworthy.
DNSSEC
Answers for this domain are signed, and the resolver validated the signature against the chain of trust up to the root.
Mail routing
Mail for this domain is delivered to these hosts, lowest preference number first.
SPF
Comfortably inside the cap of ten DNS-consuming terms.
DMARC
p=rejectReceivers are asked to reject mail that fails authentication. This is the strongest setting.
DKIM
Mail signed with these keys can be verified by receivers. Other selectors may also exist — this is a probe of common names, not a complete list.
Mail transport security
Sending servers are told to require TLS when delivering mail here, which closes the downgrade attack that plain opportunistic TLS leaves open.
Certificate authority
Only the authorities listed here may issue certificates for this domain.
Get an email the moment something on this page changes — the registration nears expiry, a certificate lapses, the nameservers move, or the SPF record is edited. Monitoring is not live yet. Leave an address and we will tell you when it is.