Skip to content
TECNICODESK

How to read your results

Most scans return three findings that matter. Here is what each one actually means for your domain.

Your DMARC policy: none, quarantine, or reject

DMARC (Domain-based Message Authentication, Reporting, and Conformance) tells receiving mail servers what to do with a message that fails authentication. A policy of p=none means "do nothing, just report", which is the right place to start but offers no protection on its own. p=quarantine sends failures to spam. p=reject refuses them outright and is the only setting that genuinely stops someone sending mail as your domain. Many firms set p=none years ago and never moved past it, which means the record exists but the spoofing protection does not.

SPF softfail versus hardfail

SPF (Sender Policy Framework) lists the servers allowed to send for your domain. A record ending in ~all is a softfail: mail from an unlisted server is accepted but marked. Ending in -all is a hardfail and is stricter. Softfail is a reasonable staging point, but leaving it there indefinitely weakens the whole chain. Watch the lookup limit too: SPF allows ten DNS lookups, and practices that have accumulated several senders often exceed it, which silently invalidates the record.

A missing DKIM selector

DKIM (DomainKeys Identified Mail) signs your outbound mail with a key published in DNS under a named selector. A scan can only check the selectors it knows to look for, so "no DKIM found" sometimes means the selector is non-standard rather than absent. It is worth confirming directly in Microsoft 365 or Google Workspace before assuming DKIM is missing. If it genuinely is not enabled, DMARC cannot be enforced safely, because legitimate mail would start failing.

The order matters: get SPF and DKIM correct first, watch the DMARC reports, then move the policy to quarantine and finally reject. Skipping to reject with an incomplete SPF record is how firms accidentally block their own invoices. See email and DMARC security services for how we run that sequence.

Want the plain-English version?

Send us your domain and we will read the results for you and reply with what to fix first, in order. No obligation.

By submitting, you agree to our Privacy Policy.

Free tool

Free Domain Security Scan

Scan your domain for DMARC, SPF, and DKIM issues that may affect email authentication, spoofing risk, and domain trust. Tecnico Desk uses EasyDMARC MSP to help small businesses review email authentication, sender sources, domain spoofing risk, and next steps for DMARC readiness.

Load the domain scanner

The scanner is provided by EasyDMARC. Loading it connects your browser to EasyDMARC and may set cookies or process the domain you enter. It loads only when you choose to.

See our Privacy Policy for details.

This scan is a starting point for visibility and review.

What this scan checks

What the scan covers

  • DMARC record visibility
  • SPF and DKIM readiness
  • Email authentication gaps
  • Domain spoofing risk indicators
  • Sender source review starting point
Limitations

What this scan does not do

  • It does not guarantee phishing prevention
  • It does not stop all spoofing by itself
  • It does not replace mailbox security
  • It does not certify compliance
  • It does not replace a full security review

Want help improving your email authentication?

Tecnico Desk helps small businesses set up and maintain SPF, DKIM, and DMARC as part of a security-first managed approach.