zonewatchdog

Report

cloudflare.com

Nothing broken found

Every check passed. Records can still change without warning — that is what monitoring is for.

Delegation

5 nameservers

OK

The domain delegates to these nameservers. Two or more, on separate infrastructure, is the usual minimum for resilience.

ns3.cloudflare.com.
ns4.cloudflare.com.
ns5.cloudflare.com.
ns6.cloudflare.com.
ns7.cloudflare.com.

Registration

Registration expires 2033-02-17

OK

That is 2360 days away.

Registrar: Cloudflare, Inc.

Registered 2009-02-17

OK

The domain is about 17 years old. Age is one of the weaker signals receivers use when deciding whether new mail from a domain is trustworthy.

DNSSEC

DNSSEC is valid

OK

Answers for this domain are signed, and the resolver validated the signature against the chain of trust up to the root.

2371 13 2 32996839a6d808afe3eb4a795a0e6a7a39a76fc52ff228b22b76f6d63826f2b9

Mail routing

4 mail exchangers

OK

Mail for this domain is delivered to these hosts, lowest preference number first.

5 mxa-canary.global.inbound.cf-emailsecurity.net.
5 mxb-canary.global.inbound.cf-emailsecurity.net.
10 mxa.global.inbound.cf-emailsecurity.net.
10 mxb.global.inbound.cf-emailsecurity.net.

SPF

SPF uses 7 of 10 lookups

OK

Comfortably inside the cap of ten DNS-consuming terms.

v=spf1 ip4:199.15.212.0/22 ip4:173.245.48.0/20 include:_spf.google.com include:spf1.mcsv.net include:spf.mandrillapp.com include:mail.zendesk.com include:stspg-customer.com include:_spf.salesforce.com -all

DMARC

DMARC policy is p=reject

OK

Receivers are asked to reject mail that fails authentication. This is the strongest setting.

v=DMARC1; p=reject; sp=reject; adkim=r; aspf=r; pct=100; rua=mailto:a1c47f179bc04efd8ee4dcd4d85dfc65@dmarc-reports.cloudflare.net,mailto:rua@cloudflare.com

DKIM

DKIM keys found at 3 selectors

OK

Mail signed with these keys can be verified by receivers. Other selectors may also exist — this is a probe of common names, not a complete list.

k1._domainkey.cloudflare.com
s1._domainkey.cloudflare.com
mandrill._domainkey.cloudflare.com

Mail transport security

MTA-STS is published

OK

Sending servers are told to require TLS when delivering mail here, which closes the downgrade attack that plain opportunistic TLS leaves open.

v=STSv1;id=1769609691387;

Certificate authority

CAA records restrict certificate issuance

OK

Only the authorities listed here may issue certificates for this domain.

0 iodef "mailto:tls-abuse@cloudflare.com"
0 issue "comodoca.com"
0 issue "digicert.com; cansignhttpexchanges=yes"
0 issue "letsencrypt.org"
0 issue "pki.goog; cansignhttpexchanges=yes"
0 issue "ssl.com"
0 issuewild "comodoca.com"
0 issuewild "digicert.com; cansignhttpexchanges=yes"
0 issuewild "letsencrypt.org"
0 issuewild "pki.goog; cansignhttpexchanges=yes"
0 issuewild "ssl.com"

Watch this domain

Get an email the moment something on this page changes — the registration nears expiry, a certificate lapses, the nameservers move, or the SPF record is edited. Monitoring is not live yet. Leave an address and we will tell you when it is.

30 DNS lookups · report valid for 60s (shortest record TTL)Checked 2026-09-02 15:04:23 UTCSPF include treeTLS certificatesCheck another domain