8 nameservers
OKThe domain delegates to these nameservers. Two or more, on separate infrastructure, is the usual minimum for resilience.
Report
Nothing is broken today. These weaken the domain or will bite later.
Delegation
The domain delegates to these nameservers. Two or more, on separate infrastructure, is the usual minimum for resilience.
Registration
Far enough away to be calm about, close enough to confirm that auto-renew is on and the payment method is current.
The domain is about 18 years old. Age is one of the weaker signals receivers use when deciding whether new mail from a domain is trustworthy.
DNSSEC
Answers for this domain are not cryptographically signed, so a resolver cannot prove they were not tampered with in transit. This is still the common case on the internet and is not a fault.
Fix: If your DNS host supports it, enabling DNSSEC is usually one switch plus a DS record at your registrar.
Mail routing
Mail for this domain is delivered to these hosts, lowest preference number first.
SPF
The record is valid, and it has no headroom. RFC 7208 allows ten DNS-consuming terms and this uses all ten, so adding one more sending service will push it over the limit. Past that, receivers stop evaluating and treat the check as failed — mail that should pass will not.
Fix: Make room before you need it. Remove senders you no longer use, or replace the deepest include: with the explicit ip4: ranges it resolves to, which cost nothing.
DMARC
p=quarantineReceivers are asked to quarantine failing mail, usually to the spam folder.
DKIM
Mail signed with these keys can be verified by receivers. Other selectors may also exist — this is a probe of common names, not a complete list.
Mail transport security
Mail to this domain is encrypted only if the sending server chooses to. An attacker positioned between the two servers can strip the offer of TLS and the mail is delivered in plain text, with no error shown to anyone.
Fix: Publish an MTA-STS policy and its TXT record. Google Workspace and Microsoft 365 both document a one-page setup.
A _smtp._tls record asks sending servers to report failed TLS connections to you. Without it, a broken certificate on your mail server produces silent delivery failures that nobody reports.
Fix: Add a TXT record at _smtp._tls.github.com with v=TLSRPTv1; rua=mailto:you@example.com.
Certificate authority
Only the authorities listed here may issue certificates for this domain.
Get an email the moment something on this page changes — the registration nears expiry, a certificate lapses, the nameservers move, or the SPF record is edited. Monitoring is not live yet. Leave an address and we will tell you when it is.