Optional categories are off until you choose. You can change or withdraw your choice using Cookie settings in the footer.

XRENN Labs s.r.o.

Security guides

SPF and DMARC: what your domain scan actually tells you

A published mail policy is useful evidence, but it is not proof that every legitimate message passes authentication. Start with the observed record and the systems that actually send your mail.

Editorial author: XRENN Labs s.r.o. · Updated:

What the policies protect

SPF identifies permitted sending systems for the envelope domain. DMARC checks alignment with the visible From domain using SPF or DKIM and expresses a handling preference. A p=none policy is monitoring, not a request to reject failures. Receiver policy still affects delivery.

Sources: IETF RFC 7208 — SPF · IETF RFC 9989 — DMARC (2026)

What our scanner measures

We query public MX, SPF and DMARC records for the submitted domain. DKIM discovery checks eight common selectors: selector1, selector2, google, default, s1, s2, k1 and mail. The report preserves the observed records and distinguishes a completed lookup from a timeout. No DNS change is required to run the scan.

What the result cannot prove

No key at those selectors does not establish that DKIM is absent everywhere. We do not send test messages or prove SPF/DKIM alignment from DNS alone. The domain-level lookup is not a complete DMARC policy-discovery engine across the DNS tree. RFC 9989 replaces RFC 7489; a domain result must not be presented as full conformance testing.

Sources: IETF RFC 9989 — DMARC (2026)

Change policy without losing legitimate mail

Inventory your mailbox provider, CRM, invoicing and bulk-mail systems first. Check their documented sending configuration and representative received-message headers. Review aggregate reports before tightening DMARC. Do not copy a blanket reject policy or delete an SPF include merely to improve a score; agree on rollback and who will watch delivery.

Sources: IETF RFC 9989 — DMARC (2026)

How to verify the improvement

After DNS propagation, compare a new scan with the exact change you made. Confirm real delivery and authentication for each sending system separately. A higher scanner score supports a configuration check; successful business mail and the remaining limitations belong in the change record too.

Editorial method and primary sources

These explanations are checked against the implemented scanner scope and the references below. They distinguish public observations from checks requiring authorized internal access. A content update is not a customer audit or an independently certified review.

Related guides

Expert guarantor

Cybersecurity, NIS2 & AI with Guarantor.

Direct contact with the expert guarantor for ISO 27001 ISMS, new Czech Cyber Security Act (ZKB 264/2025 Sb.) / NIS2 compliance, penetration testing, and world-class AI security.

Whether you are addressing the requirements of the new Czech Cyber Security Act (ZKB 264/2025 Sb.), the European NIS2 directive, ISO/IEC 27001 certification, or securely deploying frontier AI models and offline EdgeGuardian appliances, send your project inquiry to schedule an expert consultation.

Expertise & Diplomas

ISO/IEC 27001:2023 Lead Auditor

Information Security Management (ISMS), audit certification, and security policy implementation.

MBA Cybersecurity Academic Degree

Master of Business Administration – strategic and technical cybersecurity governance.

NIS2 & ZKB 264/2025 Sb. Compliance

Guarantor of compliance with the new Cyber Security Act and EU NIS2 directive.

AI & LLM Security Frontier AI

World-class frontier LLM model security, AI Red Teaming, and EdgeAI defense.