5things to fix
✗No DMARC record - domain is open to spoofing.▸
Publish a TXT record at _dmarc starting with v=DMARC1; p=none; rua=mailto:you@yourdomain, then tighten it to reject once senders pass.
Read the guide →!DNSSEC not enabled - enable it to prevent DNS spoofing.▸
Turn on DNSSEC at your DNS host, then publish the DS record at your registrar to complete the chain of trust.
Read the guide →!No HSTS header - add Strict-Transport-Security.▸
Send Strict-Transport-Security: max-age=31536000; includeSubDomains on every response, at your server or CDN edge.
Read the guide →!No Content-Security-Policy header.▸
Add a Content-Security-Policy. Start in Content-Security-Policy-Report-Only mode, refine it, then enforce.
Read the guide →!Missing X-Content-Type-Options: nosniff.▸
Add the header X-Content-Type-Options: nosniff to stop browsers MIME-sniffing responses.
Read the guide →DNS records
A172.67.129.211
104.21.2.240
AAAA2606:4700:3037::6815:2f0
2606:4700:3033::ac43:81d3
Nameserverselaine.ns.cloudflare.com.
patryk.ns.cloudflare.com.
MXdoes not receive emailNo mail
SOAelaine.ns.cloudflare.com. dns.cloudflare.com. 2411412607 10000 2400 604800 1800
Mail authentication
SPFmissing-
DMARCmissingFail
DKIMnot detected on common selectors-
DNSSEC
ZoneOff
IP intelligence
Primary IP172.67.129.211
TLS certificate
CertificateLet's Encrypt · expires 2026-11-03 (63d)Valid
HTTP security headers
HTTPS redirectYes
HSTSNo
CSPNo
X-Content-TypeNo
X-Frame-OptionsNo
Referrer-PolicyNo
Permissions-PolicyNo
Servercloudflare