MailPosture
Scan result

arc.net

0Grade AScore
Share your score: X / Twitter LinkedIn

SPF

Which servers can send email as your domain.

Warning
DNS lookups
5/10
v=spf1 include:_spf.firebasemail.com include:mail.zendesk.com ~all
  • '~all' (soft fail) is okay but '-all' (hard fail) is recommended for full protection.

DKIM

Cryptographic signature proving message integrity.

Pass
Selector
google
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsqqpAawRARLUa9vaJe1MVw0IEayVDibYJZCu3MmmTubo0lvitEzbIdDN0yIJ9Xj93UIS2yWt41D8Rjxk2HexoLFaOLSIuh3+zDfn7MZd4NdMtgKtX5X3dDTFmWBkHB/agyIfs6FYycO+DxNVgwu8MsN6vwZtV+wOmo9KKjV2p+94ktrTaqySvNZMb7NWv33qaHE/wBEM7GMZlf5Wp5EgxTduZIfiNm2ZXYkjqkm8Zz5pSdjjqQMdjnZ2AngdyyIirK3HJNBbdNVq841DpvwkHHAOdVh2h3P5E9OpI/RKLP5HAldqdSZOyowBFNJaeNqJDCTExVjH1CRa1F+NXszWJwIDAQAB

DMARC

Policy for handling messages that fail SPF/DKIM.

Pass
Policy
quarantine
Reports
Configured
RUA
reports@rua.getmailposture.com
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@arc.net,mailto:re+876ff669943f@inbound.dmarcdigests.com

MX Records

Where mail for this domain is delivered.

Pass
  • 1 aspmx.l.google.com.
  • 5 alt2.aspmx.l.google.com.
  • 5 alt1.aspmx.l.google.com.
  • 10 alt4.aspmx.l.google.com.
  • 10 alt3.aspmx.l.google.com.

Recommended fixes

Ordered by severity. Copy the record, paste it at your DNS registrar, and re-scan.

Improve your existing SPF record

medium
v=spf1 include:_spf.firebasemail.com include:mail.zendesk.com -all
  1. 1Replace your current SPF TXT record with the corrected value.
  2. 2Prefer '-all' (hard fail) once you're confident all senders are included.
  3. 3Keep total DNS lookups (include/a/mx/ptr/exists/redirect) at 10 or fewer.

DNS -> Records -> Add record -> Type: TXT -> Name: as specified -> Content: paste value -> Save.

Monitor arc.net 24/7

Get instant email alerts the moment your SPF, DKIM, or DMARC records change or break -- before it costs you deliverability.

Start monitoring

What is SPF?

SPF (Sender Policy Framework) is a DNS TXT record that lists which mail servers are authorized to send email on behalf of arc.net. Receiving servers check the sending IP against this list; anything not listed can be rejected or marked as spam.

What is DKIM?

DKIM (DomainKeys Identified Mail) cryptographically signs outgoing messages from arc.net, letting receiving servers verify the message wasn't altered in transit and genuinely came from an authorized sender.

What is DMARC?

DMARC ties SPF and DKIM together for arc.net, defining what receiving servers should do when a message fails both checks -- and where to send aggregate reports so you can monitor abuse of your domain.