How to fix it, one problem at a time.
Every problem our checks can find, with what it means, why it matters and the steps to fix it for Microsoft 365, Google Workspace, Cloudflare and other common providers.
SPF
No SPF record
Your domain has no SPF record, so receivers can't tell which servers may send its email. How to build one for Microsoft 365, Google and others.
Multiple SPF records
Two SPF records on one domain make SPF fail for every email (a permerror). How to merge them into one record without losing a sender.
SPF syntax error
An SPF record with a typo or an unknown term fails for every email. The common mistakes, how to spot them and how to correct the record.
Broken SPF include
An SPF include points at a domain with no SPF record, an invalid one or a loop, so SPF fails. How to find the bad include and replace or remove it.
SPF over 10 lookups
SPF allows 10 DNS lookups. Go over and SPF fails for every email (permerror). How to count them, cut them and keep the record under the limit.
SPF void lookups
More than two SPF lookups that return nothing makes SPF fail. What a void lookup is, why receivers stop, and how to remove the terms that cause it.
SPF +all, ?all or no all
An SPF record ending in +all lets anyone send as you; ?all or no all says nothing. How to end the record with ~all or -all safely.
SPF ptr mechanism
The SPF ptr mechanism is slow, unreliable and discouraged by RFC 7208. What it does, why to remove it and what to replace it with.
DMARC
No DMARC record
What a missing DMARC record means, why mailbox providers now expect one, and how to add a safe first record at _dmarc on any DNS host.
Multiple DMARC records
Two TXT records at _dmarc means receivers apply no DMARC policy at all. How to find the duplicates and merge them into one record.
Invalid DMARC record
Why receivers ignore a DMARC record with a typo or no p= tag, the mistakes we see most, and how to write a record that parses.
DMARC p=none or pct below 100
p=none only monitors, so spoofed email is still delivered. How to read the reports, fix your senders, and step up to quarantine and reject safely.
DMARC report address (rua)
Without rua= nobody sees who sends email as the domain. How to add a report address, send reports to two places, and authorise another domain.
DMARC forensic reports (ruf)
Forensic (ruf) reports can contain parts of real emails, and most big providers no longer send them. Why removing ruf= is usually simplest.
DKIM
DKIM not found
Why a checker finds no DKIM key for a domain, how to confirm it, and how to turn on DKIM signing in Microsoft 365, Google Workspace and other services.
Weak DKIM key
Why DKIM keys under 1024 bits fail, why 1024-bit keys should be replaced, and how to rotate to 2048-bit keys in Microsoft 365 and Google Workspace.
Broken DKIM key
Why a DKIM record's key can't be read, from copy-and-paste damage to badly split strings, and how to republish it so signatures verify.
MTA-STS and TLS-RPT
MTA-STS record missing
What MTA-STS does, why a missing or duplicate _mta-sts record leaves email open to downgrade attacks, and how to publish the record and policy file.
MTA-STS policy file not found
Why senders can't fetch your MTA-STS policy file, from certificate errors to redirects, and how to serve it correctly at the mta-sts subdomain.
MTA-STS policy invalid
How to fix an MTA-STS policy file that can't be parsed, or that leaves out one of your mail servers, before it causes delivery failures in enforce mode.
MTA-STS testing mode
What MTA-STS testing and none modes do, how to use TLS-RPT reports to decide when to enforce, and how to change mode without senders missing it.
TLS-RPT record missing
What TLS-RPT reports tell you, why a missing, duplicate or address-less record means you hear nothing, and how to publish one correctly.
Website certificates
Certificate expiring
Why a website certificate expires, how to renew it with cPanel, Let's Encrypt or Cloudflare, and how to stop it happening again.
Certificate name mismatch
Why a site shows a certificate for the wrong name, how to cover both the domain and www, and what to do when only one of them answers.
Certificate chain
Why a certificate that works in your browser fails elsewhere, and how to install the intermediate certificates the server is missing.
Domain registration and DNS
Domain expiring
What happens when a domain registration lapses, how to renew and switch on auto-renew, and how to keep a client's domain from being lost.
Domain not in DNS
What NXDOMAIN and a domain with no name servers mean, and how to get a lapsed, suspended or misconfigured domain answering again.
DNS records changed
What to do when a domain's NS, MX, A or TXT records change: how to tell an expected change from a mistake or a compromise, and how to lock DNS down.
Mail servers and blacklists
MX records missing
What happens to email when a domain has no MX records, how to add Microsoft 365 or Google Workspace MX, and when to publish a null MX instead.
Mail servers unreachable
Why a domain's mail servers don't accept connections on port 25, what it means for incoming email, and how to fix it or remove dead MX records.
Blacklisted
What a DNS blacklist listing means, when it matters, how to find and stop the cause, and how to request removal without paying anyone.
Not sure what's wrong?
Check a domain for free. Each problem it finds links to its fix.