Editorial author: XRENN Labs s.r.o. · Updated:
What the policies protect
SPF identifies permitted sending systems for the envelope domain. DMARC checks alignment with the visible From domain using SPF or DKIM and expresses a handling preference. A p=none policy is monitoring, not a request to reject failures. Receiver policy still affects delivery.
Sources: IETF RFC 7208 — SPF · IETF RFC 9989 — DMARC (2026)
What our scanner measures
We query public MX, SPF and DMARC records for the submitted domain. DKIM discovery checks eight common selectors: selector1, selector2, google, default, s1, s2, k1 and mail. The report preserves the observed records and distinguishes a completed lookup from a timeout. No DNS change is required to run the scan.
What the result cannot prove
No key at those selectors does not establish that DKIM is absent everywhere. We do not send test messages or prove SPF/DKIM alignment from DNS alone. The domain-level lookup is not a complete DMARC policy-discovery engine across the DNS tree. RFC 9989 replaces RFC 7489; a domain result must not be presented as full conformance testing.
Sources: IETF RFC 9989 — DMARC (2026)
Change policy without losing legitimate mail
Inventory your mailbox provider, CRM, invoicing and bulk-mail systems first. Check their documented sending configuration and representative received-message headers. Review aggregate reports before tightening DMARC. Do not copy a blanket reject policy or delete an SPF include merely to improve a score; agree on rollback and who will watch delivery.
Sources: IETF RFC 9989 — DMARC (2026)
How to verify the improvement
After DNS propagation, compare a new scan with the exact change you made. Confirm real delivery and authentication for each sending system separately. A higher scanner score supports a configuration check; successful business mail and the remaining limitations belong in the change record too.
Editorial method and primary sources
These explanations are checked against the implemented scanner scope and the references below. They distinguish public observations from checks requiring authorized internal access. A content update is not a customer audit or an independently certified review.