zonewatchdog

Report

nasa.gov

Nothing broken found

Every check passed. Records can still change without warning — that is what monitoring is for.

Delegation

6 nameservers

OK

The domain delegates to these nameservers. Two or more, on separate infrastructure, is the usual minimum for resilience.

a1-32.akam.net.
a5-66.akam.net.
a8-66.akam.net.
a9-64.akam.net.
a12-64.akam.net.
a14-67.akam.net.

Registration

Registration expires 2027-07-31

OK

That is 331 days away.

Registrar: get.gov

Registered 1997-10-02

OK

The domain is about 28 years old. Age is one of the weaker signals receivers use when deciding whether new mail from a domain is trustworthy.

DNSSEC

DNSSEC is valid

OK

Answers for this domain are signed, and the resolver validated the signature against the chain of trust up to the root.

59470 8 2 a4d0e150872a3b60e0984c005ebdc7a7fb860ee69d8334db924989ee4175e30e

Mail routing

1 mail exchangers

OK

Mail for this domain is delivered to these hosts, lowest preference number first.

0 nasa-gov.mail.protection.outlook.com.

SPF

SPF uses 9 of 10 lookups

OK

Inside the cap, with little room left. Adding one or two more sending services would reach the limit of ten.

v=spf1 include:_spf-4a.nasa.gov include:_spf-4b.nasa.gov include:_spf-4c.nasa.gov include:_spf-4d.nasa.gov include:_spf-4g.nasa.gov include:_spf-4m.nasa.gov include:_spf-4x.nasa.gov include:_spf-6a.nasa.gov include:spf.protection.outlook.com -all

DMARC

DMARC policy is p=reject

OK

Receivers are asked to reject mail that fails authentication. This is the strongest setting.

v=DMARC1; p=reject; fo=1; rua=mailto:dmarcmail@mail.nasa.gov,mailto:reports@dmarc.cyber.dhs.gov

DKIM

DKIM keys found at 1 selector

OK

Mail signed with these keys can be verified by receivers. Other selectors may also exist — this is a probe of common names, not a complete list.

selector1._domainkey.nasa.gov

Mail transport security

No MTA-STS policy

Info

Mail to this domain is encrypted only if the sending server chooses to. An attacker positioned between the two servers can strip the offer of TLS and the mail is delivered in plain text, with no error shown to anyone.

Fix: Publish an MTA-STS policy and its TXT record. Google Workspace and Microsoft 365 both document a one-page setup.

No TLS reporting

Info

A _smtp._tls record asks sending servers to report failed TLS connections to you. Without it, a broken certificate on your mail server produces silent delivery failures that nobody reports.

Fix: Add a TXT record at _smtp._tls.nasa.gov with v=TLSRPTv1; rua=mailto:you@example.com.

Certificate authority

No CAA record

Info

Any certificate authority in the world may issue a certificate for this domain. A CAA record narrows that to the ones you actually use, so a mis-issued certificate is refused at the point of issue rather than discovered later.

Fix: Publish a CAA record naming your CA, for example 0 issue "letsencrypt.org".

Watch this domain

Get an email the moment something on this page changes — the registration nears expiry, a certificate lapses, the nameservers move, or the SPF record is edited. Monitoring is not live yet. Leave an address and we will tell you when it is.

33 DNS lookups · report valid for 298s (shortest record TTL)Checked 2026-09-02 15:02:18 UTCSPF include treeTLS certificatesCheck another domain