6 nameservers
OKThe domain delegates to these nameservers. Two or more, on separate infrastructure, is the usual minimum for resilience.
Report
Every check passed. Records can still change without warning — that is what monitoring is for.
Delegation
The domain delegates to these nameservers. Two or more, on separate infrastructure, is the usual minimum for resilience.
Registration
That is 331 days away.
The domain is about 28 years old. Age is one of the weaker signals receivers use when deciding whether new mail from a domain is trustworthy.
DNSSEC
Answers for this domain are signed, and the resolver validated the signature against the chain of trust up to the root.
Mail routing
Mail for this domain is delivered to these hosts, lowest preference number first.
SPF
Inside the cap, with little room left. Adding one or two more sending services would reach the limit of ten.
DMARC
p=rejectReceivers are asked to reject mail that fails authentication. This is the strongest setting.
DKIM
Mail signed with these keys can be verified by receivers. Other selectors may also exist — this is a probe of common names, not a complete list.
Mail transport security
Mail to this domain is encrypted only if the sending server chooses to. An attacker positioned between the two servers can strip the offer of TLS and the mail is delivered in plain text, with no error shown to anyone.
Fix: Publish an MTA-STS policy and its TXT record. Google Workspace and Microsoft 365 both document a one-page setup.
A _smtp._tls record asks sending servers to report failed TLS connections to you. Without it, a broken certificate on your mail server produces silent delivery failures that nobody reports.
Fix: Add a TXT record at _smtp._tls.nasa.gov with v=TLSRPTv1; rua=mailto:you@example.com.
Certificate authority
Any certificate authority in the world may issue a certificate for this domain. A CAA record narrows that to the ones you actually use, so a mis-issued certificate is refused at the point of issue rather than discovered later.
Fix: Publish a CAA record naming your CA, for example 0 issue "letsencrypt.org".
Get an email the moment something on this page changes — the registration nears expiry, a certificate lapses, the nameservers move, or the SPF record is edited. Monitoring is not live yet. Leave an address and we will tell you when it is.