Northwind Traders
northwindtraders.onmicrosoft.com
SPF, DMARC and DKIM stop other people sending email as the client's domains. MTA-STS and TLS-RPT make other servers deliver mail to them encrypted, and report when they can't.
| Domain | Receives mail via | SPF | DMARC | DKIM | MTA-STS | TLS-RPT |
|---|---|---|---|---|---|---|
| northwindtraders.example medium | Microsoft 365 | Pass | Weak | Weak | Missing | Missing |
What to fix: DMARC is monitor-only (p=none); spoofed mail is still delivered; Microsoft 365 DKIM isn't set up (selector2 CNAME missing); No MTA-STS policy, so mail sent to this domain can be forced onto an unencrypted connection | ||||||
| parked.example low | Doesn't receive mail | Missing | Missing | n/a | n/a | n/a |
What to fix: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing; Doesn't receive mail but has no DMARC p=reject record | ||||||
| Domain | SPF record | DNS lookups | DMARC record | MTA-STS policy | MX |
|---|---|---|---|---|---|
| northwindtraders.example | v=spf1 include:spf.protection.outlook.com -all | 1 | v=DMARC1; p=none; rua=mailto:dmarc@northwindtraders.example | None | northwindtraders-example.mail.protection.outlook.com |
| parked.example | None | None | None |
Data from Email domains ().