Findings Knowledge Base
No entries match.
TLS & Encryption
tls.cert.dane_ee_pinned— Certificate Pinned by DANE-EEThe server relies on DANE rather than a certificate authority to prove its identity. A DANE-EE record publishes the certificate (or its public key) in DNS,…tls.cert.expired— Certificate ExpiredThe server's TLS certificate has expired. Every certificate has a fixed validity window (notBefore to notAfter); once notAfter passes, the certificate is no…tls.cert.expiring_soon— Certificate Expiring SoonThe server's TLS certificate is valid now but will expire within 30 days. Once it expires, sending servers that verify certificates will refuse delivery,…tls.cert.hostname_mismatch— Certificate Hostname MismatchThe certificate presented by this IP is not valid for the MX hostname. The certificate may be perfectly valid for a different hostname — but it does not…tls.cert.hostname_shared_frontend— Certificate for Shared Mail Front-EndThe certificate is not valid for your MX hostname, but it does cover the machine's own PTR-confirmed hostname. This is consistent with a shared mail…tls.cert.invalid_chain— Certificate Chain InvalidThe certificate chain presented by the server could not be validated. Common causes:tls.cert.not_revoked— Certificate Not RevokedThe certificate authority confirms that this certificate is valid and has not been revoked. This is the expected, healthy state — the CA vouches for the…tls.cert.ocsp_not_applicable— OCSP Stapling Not ApplicableThe certificate does not include an OCSP responder URL, so OCSP stapling cannot apply to this server. This is not a misconfiguration — the certificate…tls.cert.ocsp_not_stapled— No OCSP StaplingThe server does not include an OCSP response in the TLS handshake, even though the certificate provides an OCSP responder URL. Without stapling, clients…tls.cert.ocsp_stapled— OCSP Stapling EnabledThe server staples a valid OCSP response in the TLS handshake. This is the best practice for servers whose certificates include an OCSP responder — it…tls.cert.revocation_not_published— No Revocation Endpoint PublishedThe certificate does not publish any revocation endpoint that our checks can use. This is increasingly common and not a defect — Let's Encrypt retired its…tls.cert.revocation_unavailable— Revocation Status UnavailableWe tried to check whether the certificate has been revoked, but the authority's endpoint was unreachable, timed out, or returned an unparseable response.…tls.cert.revocation_unknown— Revocation Status UnknownThe certificate authority answered the revocation query but reported that it does not recognize this certificate — the serial number is not in its records.…tls.cert.revoked— Certificate RevokedThe certificate authority has explicitly revoked this certificate. Revocation means the CA no longer vouches for it, regardless of whether it is within its…tls.cert.sct_missing— No Certificate Transparency (SCT Missing)No Signed Certificate Timestamps were found. The certificate was either not submitted to a public Certificate Transparency log, or the SCTs are not being…tls.cert.sct_present— Certificate Transparency (SCT Present)The server provides valid SCTs, proving its certificate was logged in at least one public CT log. This is the expected, healthy state for certificates…tls.cert.self_signed— Self-Signed CertificateThe server presents a certificate it signed itself — no certificate authority has verified the server operator's identity. Any party can generate a…tls.cert.weak_sig_alg— Weak Signature Algorithm (SHA-1/MD5)The server's certificate was signed using SHA-1 or MD5. An attacker with sufficient resources could forge a certificate with the same signature, undermining…tls.cipher.no_pfs— No Perfect Forward SecrecyThe server negotiated a cipher suite without forward secrecy — typically a plain RSA key exchange (e.g., TLS_RSA_WITH_AES_256_CBC_SHA). If the server's…tls.cipher.weak— Weak Cipher Suites SupportedThe mail server accepts connections using cipher suites with known cryptographic weaknesses. These ciphers either use broken algorithms (RC4), insufficient…tls.dane.lookup_error— DANE/TLSA Lookup FailedThe DNS query for TLSA records failed with a transient error. This does not mean TLSA records are absent — it means the authoritative DNS servers did not…tls.dane.mismatch— DANE/TLSA MismatchThe domain publishes a DANE/TLSA record that is DNSSEC-signed and structurally valid, but the certificate the mail server presents does not match it. This…tls.dane.missing— No DANE/TLSA RecordsNo TLSA records were found for the MX hostname. DANE is not configured. This is the default state for most domains — DANE adoption requires DNSSEC on the…tls.dane.unsigned— DANE/TLSA Records Lack Resolver-Attested DNSSECTLSA records exist for the MX hostname, but the DNS response does not carry DNSSEC authentication. Either the domain's zone is not DNSSEC-signed, the…tls.dane.unverified— DANE/TLSA Not VerifiedTLSA records are published and may be valid, but we were unable to confirm or deny a match against the server's certificate. The DANE configuration is…tls.dane.valid— DANE/TLSA ValidatedThe mail server's TLS certificate is authenticated by a DNSSEC-signed TLSA record. DANE-enforcing senders can cryptographically verify that they are talking…tls.legacy_key_exchange— Legacy TLS Key Exchange OnlyThe server's TLS configuration uses only legacy key exchange methods. While TLS connections still work, the key exchange is weaker than current…tls.mtasts.lookup_error— MTA-STS DNS Lookup FailedThe DNS query for the MTA-STS record failed with a transient error. We cannot determine whether an MTA-STS configuration exists.tls.mtasts.missing— MTA-STS Not ConfiguredNo MTA-STS configuration was found — neither the DNS record nor the policy file exists. Without MTA-STS, sending servers use opportunistic TLS: they attempt…tls.mtasts.mode_none— MTA-STS Disabled (mode=none)An MTA-STS policy file exists, but its mode is set to none. This tells sending servers that MTA-STS is not active — they should not enforce TLS requirements…tls.mtasts.mx_mismatch— MTA-STS MX Patterns IncompleteThe MTA-STS policy exists and is valid, but its mx: patterns do not cover all of the domain's MX hostnames. MX targets not listed in the policy are…tls.mtasts.policy_error— MTA-STS Policy UnreadableThe domain advertises MTA-STS via its DNS record, but the policy file is broken — it may have invalid syntax, missing required fields (version, mode, mx,…tls.mtasts.policy_unavailable— MTA-STS Policy Temporarily UnavailableThe MTA-STS DNS record signals that a policy should exist, but the policy file could not be fetched at the time of the scan. This is likely a transient…tls.mtasts.testing— MTA-STS in Testing ModeThe MTA-STS policy is in testing mode. Sending servers will check certificate validity and report failures via TLS-RPT, but they will not refuse delivery…tls.not_applicable— TLS Not Applicable (Null MX)The domain has a valid Null MX record, so TLS testing does not apply. There are no SMTP servers to connect to, no certificates to verify, and no STARTTLS to…tls.not_tested— TLS Not Tested (No SMTP Session)The domain has MX records pointing to resolvable hosts, but we could not complete an SMTP session with any of them. Without a session, STARTTLS negotiation…tls.tlsrpt.lookup_error— TLS-RPT DNS Lookup FailedThe DNS query for the TLS-RPT record failed with a transient error. We cannot determine whether a TLS-RPT record exists.tls.tlsrpt.missing— TLS-RPT Not ConfiguredNo TLS-RPT record was found. Without it, sending servers that encounter TLS problems delivering to your domain have no way to report them to you. TLS…tls.tlsrpt.present— TLS-RPT ConfiguredThe domain publishes a TLS-RPT record, enabling sending servers to report TLS negotiation failures. This is a positive configuration signal — the domain…tls.untestable— TLS Not TestableTLS cannot be tested because there is no mail server to connect to. This is a consequence of the MX configuration, not a TLS problem in itself. The fix is…tls.version.no_tls12— TLS 1.2 Not SupportedThe mail server cannot negotiate TLS 1.2 — the minimum protocol version considered secure by current standards. The server may still offer TLS 1.0 or 1.1,…tls.version.tls10— TLS 1.0 SupportedThe mail server still supports TLS 1.0, a protocol version formally deprecated by RFC 8996 (2021). TLS 1.0 has known cryptographic weaknesses (BEAST,…tls.version.tls11— TLS 1.1 SupportedThe mail server still supports TLS 1.1, a protocol version formally deprecated by RFC 8996 (2021). TLS 1.1 shares many of TLS 1.0's structural limitations —…tls.version.tls13— TLS 1.3 SupportedThe mail server supports TLS 1.3 — the latest version of the TLS protocol. TLS 1.3 is a significant improvement over 1.2: it removes legacy cipher suites,…tls.version.tls13_only— TLS 1.3 OnlyThe server runs the most modern transport configuration there is: only TLS 1.3, with its mandatory forward secrecy and AEAD-only cipher suites. From a…
Email Authentication
auth.dkim.lookup_error— DKIM DNS Lookup FailedA DKIM DNS query didn't complete. This is not a statement that DKIM is missing or misconfigured — the scanner simply couldn't get a clean answer during this…auth.dkim.missing— No DKIM Key FoundNo DKIM public keys were found at the selectors we probe. Either the domain doesn't sign its mail with DKIM, or it signs with a selector name we didn't…auth.dkim.missing_null_mx— No DKIM Keys (Null MX Domain)On an ordinary mail domain, missing DKIM keys are a failure. On a Null MX domain they may simply mean the domain sends no mail either — in which case there…auth.dkim.revoked— DKIM Key RevokedOne or more DKIM selectors on this domain publish a record with p= and nothing after it. That is not a broken record — it's a deliberate revocation. A…auth.dkim.revoked_null_mx— DKIM Keys Revoked (Null MX Domain)On an ordinary mail domain a revoked key is a failure: mail signed with it can no longer be verified. On a Null MX domain the picture is different.…auth.dkim.strict_mode— DKIM Key Restricted to Exact Domain (t=s)A DKIM selector on this domain sets t=s, so signatures made with this key only verify when the d= domain and the i= identity domain match exactly. Without…auth.dkim.testing_mode— DKIM Testing Mode EnabledA DKIM selector on this domain has t=y set. In testing mode, receivers are instructed to ignore DKIM failures for this key — which means the signature…auth.dkim.unparseable_key— DKIM Key Could Not Be ReadA DKIM record exists, but its p= value doesn't parse as a valid public key. This is different from a missing key (nothing published) and from a revoked key…auth.dkim.weak_hash_algorithm— DKIM Allows SHA-1 SignaturesA DKIM key on this domain lists sha1 as an acceptable hash algorithm. SHA-1 is broken for cryptographic signatures — practical collision attacks exist — so…auth.dkim.weak_key— DKIM RSA Key Too SmallA DKIM key on this domain is shorter than 2048 bits. Short RSA keys can be factored with modern computing resources — and a factored key lets an attacker…auth.dmarc.alignment_mode— DMARC Alignment ModeThis is an informational finding that reports the domain's alignment configuration — it is neither a pass nor a failure. DMARC only passes when a passing…auth.dmarc.deprecated_tag— Deprecated DMARC TagsYour DMARC record contains one or more tags that the updated specification no longer defines:auth.dmarc.external_unauthorized— External DMARC Report Destination Not AuthorizedYour DMARC record points reports at an address on another domain — typically a third-party DMARC-reporting service — but that domain has not published the…auth.dmarc.invalid_policy— DMARC Policy Not ValidRFC 7489 §6.6.3 tells receivers exactly what to do with such a record: if it names an aggregate-report destination (rua=), act as if p=none had been…auth.dmarc.invalid_tag_value— Invalid DMARC Tag ValueThe record is not the record you think you published. A common example is fo=0,1,s — commas instead of colons — which no receiver can interpret as a…auth.dmarc.lookup_error— DMARC DNS Lookup FailedA DMARC DNS query didn't complete. This isn't a statement that DMARC is missing or misconfigured — the scanner simply couldn't get a clean answer during…auth.dmarc.missing— DMARC Record MissingNo DMARC record was found at _dmarc.<domain>. Without one, receiving servers have no policy to enforce: they may deliver, junk, or drop unauthenticated mail…auth.dmarc.multiple_records— Multiple DMARC RecordsThe domain publishes more than one DMARC record at _dmarc.<domain>. Receivers can't pick between them, so per the specification they discard them all and…auth.dmarc.no_rua— DMARC Missing Aggregate Report URIThe DMARC record has no rua= destination. The policy may enforce correctly, but you receive no aggregate reports — so you have no visibility into who is…auth.dmarc.none— DMARC Policy Is 'none'A DMARC record exists, but its policy is none. Under RFC 7489, none requests no action against failing mail — receivers deliver it normally and simply…auth.dmarc.pct_partial— DMARC Policy Not Fully EnforcedYour DMARC policy is set to quarantine or reject, but pct= is below 100 — so only that percentage of failing messages gets the enforcement action. The rest…auth.dmarc.quarantine— DMARC Policy Is 'quarantine'Quarantine asks receivers to treat mail that fails DMARC as suspicious. In practice that means the spam or junk folder, sometimes a warning banner; the…auth.dmarc.sp_none— DMARC Subdomain Policy Is 'none'The organizational domain is enforced, but every subdomain is not. RFC 7489 §6.3 lets sp= override p= for subdomains, and none requests no action against…auth.spf.duplicate_include— Duplicate SPF IncludeYour SPF record resolves the same include: target more than once. This is harmless to authentication — the extra pass returns the same answer — but it's…auth.spf.lookup_error— SPF DNS Lookup FailedAn SPF DNS lookup did not complete, so the policy result is indeterminate. This is not a statement about your record's correctness — it's an operational…auth.spf.lookup_limit— SPF DNS Lookup Limit ExceededYour SPF record needs more than 10 DNS lookups to evaluate. Once a receiver crosses that limit it stops and returns a PermError — SPF fails permanently,…auth.spf.missing— SPF Record MissingNo SPF record was found at the domain apex. Receivers have no published list of authorized sending IPs, so they cannot use SPF to distinguish your…auth.spf.multiple_records— Multiple SPF RecordsThe domain publishes more than one v=spf1 record. Receivers cannot choose between them, so the specification requires them to treat the result as a…auth.spf.neutral_all— SPF Neutral Policy (?all)Neutral means the domain explicitly declines to say whether an unlisted server may send its mail. RFC 7208 §2.6.2 tells receivers to treat a neutral result…auth.spf.no_all— SPF Record Has No "all" MechanismRFC 7208 §4.7 defines what happens when no mechanism matches and there is no all: the result is neutral, exactly as if the record ended in ?all. Every…auth.spf.permerror— SPF Record InvalidThe SPF policy has a permanent error and cannot be evaluated reliably. Receivers that hit a PermError treat SPF as broken — the record provides no…auth.spf.plus_all— SPF +all (Open SPF)The record ends in +all, which returns a pass for every server on the internet. Anyone, anywhere, is authorized to send mail as your domain — SPF protection…auth.spf.ptr_mechanism— Deprecated PTR MechanismYour SPF record uses ptr. To evaluate it, a receiver has to reverse-look-up the connecting IP to a hostname, then forward-look-up that hostname to confirm…auth.spf.record_too_long— SPF Record Too LongThe SPF record is large enough to risk UDP truncation. A single TXT record can hold multiple quoted strings, but the overall record has grown big enough…auth.spf.sender_id_deprecated— Deprecated Sender ID RecordAlongside your SPF record, the domain publishes a legacy spf2.0/ Sender ID record. Modern receivers don't use Sender ID, so the record does nothing useful —…auth.spf.softfail_all— SPF Soft-Fails Unauthorized Senders (~all)A softfail tells receivers that mail from a server the record does not list is probably not authorized, without asking them to reject it. Most receivers…auth.spf.void_lookups_exceeded— SPF Void Lookup Limit ExceededYour SPF record triggers more than two DNS lookups that resolve to nothing. Each include:, a, mx, exists:, or ptr term that points at a non-existent record…
SMTP Session
smtp.banner.hostname_mismatch— Banner Hostname Does Not Match MX HostnameThe hostname in the SMTP banner does not match the MX hostname that DNS resolved. For example, the MX record says mail.example.com, but the banner says 220…smtp.banner.invalid_fqdn— Invalid Hostname in SMTP BannerThe SMTP banner contains a hostname that is not a valid FQDN — it may be a bare hostname without a domain part (e.g., localhost, mail), an IP address…smtp.banner.version_leak— MTA Software Leaked in BannerThe SMTP banner includes the MTA software name and/or version number (e.g., Postfix 3.5.6, Exim 4.96, Microsoft ESMTP MAIL Service). While not a…smtp.ehlo.no_8bitmime— 8BITMIME Not AdvertisedThe server does not advertise the 8BITMIME extension in its EHLO response. Without it, senders must encode all non-ASCII content (international characters,…smtp.ehlo.no_pipelining— PIPELINING Not AdvertisedThe server does not advertise the PIPELINING extension in its EHLO response. Without it, every SMTP command requires a separate round-trip — the sender must…smtp.ehlo.no_size— SIZE Limit Not AdvertisedThe server does not advertise the SIZE extension in its EHLO response. Without it, senders have no way to know the maximum message size before attempting…smtp.ehlo.no_smtputf8— SMTPUTF8 Not AdvertisedThe server does not advertise the SMTPUTF8 extension in its EHLO response. Senders cannot deliver mail addressed to internationalized email addresses (EAI)…smtp.expn.enabled— EXPN Command EnabledThe server responds to EXPN commands, revealing the individual recipients behind mailing list aliases. An attacker can use this to discover internal…smtp.open_relay— Open Relay DetectedThe server accepted a mail relay request from an unauthenticated external sender to an external recipient. This means anyone on the internet can use this…smtp.rfc2142.abuse— abuse@ Not Accepting MailThe server rejected RCPT TO:<abuse@domain>. The abuse address is either not configured, aliased to a non-existent mailbox, or explicitly blocked by…smtp.rfc2142.postmaster— postmaster@ Not Accepting MailThe server rejected RCPT TO:<postmaster@domain>. The postmaster address is either not configured, aliased to a non-existent mailbox, or explicitly blocked…smtp.session.aborted— SMTP Session Closed by ServerThe server hung up before the scanner was done. The usual trigger is the scanner's own deliberately failing relay probe: Postfix counts the refused RCPT TO…smtp.session.unavailable— SMTP Session Not EstablishedThe server accepted the connection, but no session with the scanner came about. Common causes:smtp.starttls.failed— STARTTLS Negotiation FailedThe server claims to support STARTTLS but the TLS handshake broke down. Common causes: a misconfigured or missing certificate, an incompatible TLS version,…smtp.starttls.intermittent— Intermittent STARTTLS AdvertisementThe server's STARTTLS advertisement is inconsistent — it appeared in one of two probes but not both. This typically indicates a load balancer routing to…smtp.starttls.missing— STARTTLS Not AdvertisedThe server did not advertise STARTTLS in either SMTP session. All mail delivered to this server travels in plain text — readable by anyone on the network…smtp.starttls.not_required— STARTTLS Not Required (Opportunistic TLS)The server offers STARTTLS but does not require it. A sender that supports TLS will negotiate encryption; a sender that does not (or a network attacker that…smtp.vrfy.enabled— VRFY Command EnabledThe server responds to VRFY commands, confirming or denying the existence of individual mailboxes. An attacker can use this to enumerate valid email…
MX & DNS
mx.all_targets_ip_literal— All MX Targets Are IP LiteralsEvery MX record for the domain points to an IP address literal instead of a hostname. The domain effectively has no hostname-based mail routing — the same…mx.endpoint.all_unreachable— No MX Endpoint ReachableThe domain publishes MX records, but nothing behind them accepts mail from the public internet right now. Every sender that tries will queue the message,…mx.endpoint.unreachable— MX Endpoint UnreachablePart of the domain's published mail infrastructure is dead from the public internet. Every sending server that picks that endpoint first — MX preference and…mx.implicit— No MX Record (Implicit MX)The domain has no MX records, but it does have an A or AAAA record. Sending servers will fall back to delivering mail directly to the IP address of the…mx.ip_literal— MX Record Points to IP AddressAt least one MX record points to an IP address literal instead of a hostname. While some sending servers will attempt delivery to the literal address, this…mx.lookup_error— MX DNS Lookup FailedThe DNS query for MX records failed with a transient error. This does not mean MX records are absent — it means the authoritative DNS servers for the domain…mx.missing— No MX RecordsThe domain has no MX records and no A/AAAA record to fall back on. No sending server can determine where to deliver email for this domain — mail is…mx.no_redundancy— Single MX Target (No Redundancy)The domain's MX records resolve to a single IP address. There is no backup mail server. If the primary server goes offline — for maintenance, hardware…mx.no_usable_targets— No Usable MX TargetThe domain has MX records, but every single target is unusable — none can actually receive mail. This is functionally identical to having no MX records:…mx.null_mx— Null MX (Domain Does Not Accept Email)The domain has published a valid Null MX record. This is a positive signal: the domain has explicitly declared that it does not accept inbound email, and…mx.null_mx_invalid— Null MX Coexists With Other MX RecordsThe domain publishes a Null MX (declaring it does not accept email) alongside one or more regular MX records (pointing to mail servers). This is a…mx.nxdomain— Domain Does Not ExistThe domain you scanned is not registered, has expired, or is not delegated from its parent zone. There is no mail setup to audit: SPF, DKIM, DMARC, MTA-STS…mx.ptr.hostname_differs— PTR Hostname Differs From MX HostnameThe IP's reverse DNS points to a hostname that differs from the MX hostname. For example, the domain publishes mail.example.com as its MX target, the IP…mx.ptr.missing— FCrDNS Mismatch on MX HostThe MX IP address lacks a valid FCrDNS entry. Either no PTR record exists for the IP, or the PTR hostname does not resolve back to the same IP. The mail…mx.ptr.multiple_records— Multiple PTR Records on MX IPThe MX IP address has more than one PTR record. While DNS allows multiple PTR records for a single IP, and all of them may individually pass FCrDNS, the…mx.target_unresolvable— MX Target Hostname Does Not ResolveAn MX record points to a hostname that does not exist in DNS or has no address records. Sending servers cannot determine an IP address for this MX target…mx.target.invalid_hostname— MX Target Is Not a Valid HostnameAn MX record contains a target that is not a syntactically valid hostname. This is distinct from a hostname that simply does not resolve…
Bonus
bonus.bimi.dmarc_not_enforced— BIMI Published Without DMARC EnforcementThe domain publishes a BIMI record, but its DMARC policy isn't at enforcement — it's p=none, or it's quarantine/reject with a pct below 100. Clients that…bonus.bimi.logo_not_svg— BIMI Logo Not Valid SVGThe BIMI logo URL is reachable, but what it returns isn't a valid SVG. The record and the hosting are fine — the image itself is the wrong format. A PNG,…bonus.bimi.logo_unreachable— BIMI Logo Not ReachableThe BIMI record names a logo URL, but we couldn't fetch it — the HTTPS request failed, timed out, returned an error status, or the host is unreachable. A…bonus.bimi.lookup_error— BIMI DNS Lookup FailedA BIMI DNS query didn't complete. This isn't a statement that BIMI is missing or misconfigured — the scanner simply couldn't get a clean answer during this…bonus.bimi.missing— BIMI Not ConfiguredThe domain publishes no BIMI record. That is not a security problem — BIMI is an optional display feature, not an authentication mechanism. It shows your…bonus.bimi.no_logo— BIMI Record Missing Logo URLThe domain publishes a BIMI record, but it has no l= logo URL. The record is technically present but does nothing: BIMI's entire purpose is to point at a…bonus.bimi.present— BIMI ConfiguredThe domain publishes a valid BIMI record with a reachable SVG logo. This is the healthy configured state: supporting inboxes can retrieve your logo and…bonus.bimi.vmc_expired— BIMI Evidence Certificate Outside Validity WindowThe VMC leaf certificate is expired — or, more rarely, not yet valid. Mail providers that require a VMC re-validate it when deciding whether to display the…bonus.bimi.vmc_invalid— BIMI Evidence Certificate InvalidThe document at the a= URL is reachable but is not a structurally valid VMC. The finding names which check failed:bonus.bimi.vmc_present— BIMI Evidence Certificate PresentThe a= evidence certificate passed every structural check. Mail providers that require a VMC (notably Gmail and Apple Mail) have a well-formed document to…bonus.bimi.vmc_unreachable— BIMI Evidence Certificate Not ReachableThe a= tag points at a document nobody can retrieve. Mail providers that require a VMC before displaying the BIMI logo (notably Gmail and Apple Mail) fetch…bonus.dane— DANE/TLSA ValidatedThe domain has deployed DANE — a DNSSEC-authenticated TLSA record that matches the mail server's certificate. This is the strongest form of SMTP transport…bonus.mtasts.enforce— MTA-STS EnforcedThe domain publishes an MTA-STS policy with mode: enforce. Sending servers that support MTA-STS will require TLS for connections to this domain's MX hosts…bonus.tls13— TLS 1.3 SupportedThe mail server supports TLS 1.3 — the latest and most secure version of TLS. This is a positive bonus signal indicating a modern TLS configuration that…