How to read your results
Most scans return three findings that matter. Here is what each one actually means for your domain.
Your DMARC policy: none, quarantine, or reject
DMARC (Domain-based Message Authentication, Reporting, and Conformance) tells receiving mail servers what to do with a message that fails authentication. A policy of p=none means "do nothing, just report", which is the right place to start but offers no protection on its own. p=quarantine sends failures to spam. p=reject refuses them outright and is the only setting that genuinely stops someone sending mail as your domain. Many firms set p=none years ago and never moved past it, which means the record exists but the spoofing protection does not.
SPF softfail versus hardfail
SPF (Sender Policy Framework) lists the servers allowed to send for your domain. A record ending in ~all is a softfail: mail from an unlisted server is accepted but marked. Ending in -all is a hardfail and is stricter. Softfail is a reasonable staging point, but leaving it there indefinitely weakens the whole chain. Watch the lookup limit too: SPF allows ten DNS lookups, and practices that have accumulated several senders often exceed it, which silently invalidates the record.
A missing DKIM selector
DKIM (DomainKeys Identified Mail) signs your outbound mail with a key published in DNS under a named selector. A scan can only check the selectors it knows to look for, so "no DKIM found" sometimes means the selector is non-standard rather than absent. It is worth confirming directly in Microsoft 365 or Google Workspace before assuming DKIM is missing. If it genuinely is not enabled, DMARC cannot be enforced safely, because legitimate mail would start failing.
The order matters: get SPF and DKIM correct first, watch the DMARC reports, then move the policy to quarantine and finally reject. Skipping to reject with an incomplete SPF record is how firms accidentally block their own invoices. See email and DMARC security services for how we run that sequence.
Want the plain-English version?
Send us your domain and we will read the results for you and reply with what to fix first, in order. No obligation.
Keep reading
Guide
Small business security briefing
Current threats aimed at small firms, in plain English.
Guide
Microsoft 365 security checklist
The identity, email, and sharing settings that matter most in M365.
Guide
Google Workspace security checklist
The admin settings worth checking first in a Workspace tenant.
Free tool
Free Domain Security Scan
Scan your domain for DMARC, SPF, and DKIM issues that may affect email authentication, spoofing risk, and domain trust. Tecnico Desk uses EasyDMARC MSP to help small businesses review email authentication, sender sources, domain spoofing risk, and next steps for DMARC readiness.
Load the domain scanner
The scanner is provided by EasyDMARC. Loading it connects your browser to EasyDMARC and may set cookies or process the domain you enter. It loads only when you choose to.
See our Privacy Policy for details.
This scan is a starting point for visibility and review.
What the scan covers
- DMARC record visibility
- SPF and DKIM readiness
- Email authentication gaps
- Domain spoofing risk indicators
- Sender source review starting point
What this scan does not do
- It does not guarantee phishing prevention
- It does not stop all spoofing by itself
- It does not replace mailbox security
- It does not certify compliance
- It does not replace a full security review
Want help improving your email authentication?
Tecnico Desk helps small businesses set up and maintain SPF, DKIM, and DMARC as part of a security-first managed approach.