6things to fix
✗Multiple SPF records - receivers will reject; keep exactly one.▸
Merge every v=spf1 entry into a single TXT record. Combine the include: statements from each provider into one line ending in -all.
Read the guide →✗No DMARC record - domain is open to spoofing.▸
Publish a TXT record at _dmarc starting with v=DMARC1; p=none; rua=mailto:you@yourdomain, then tighten it to reject once senders pass.
Read the guide →!No IPv6 (AAAA) record.▸
Add an AAAA record with your server's IPv6 address, or switch on IPv6 at your host or CDN (on Cloudflare it's on by default for proxied records).
!DNSSEC not enabled - enable it to prevent DNS spoofing.▸
Turn on DNSSEC at your DNS host, then publish the DS record at your registrar to complete the chain of trust.
Read the guide →!No Content-Security-Policy header.▸
Add a Content-Security-Policy. Start in Content-Security-Policy-Report-Only mode, refine it, then enforce.
Read the guide →!Missing X-Content-Type-Options: nosniff.▸
Add the header X-Content-Type-Options: nosniff to stop browsers MIME-sniffing responses.
Read the guide →DNS records
A198.185.159.145
198.49.23.144
198.49.23.145
198.185.159.144
AAAAnone
Nameserversdns1.p02.nsone.net.
dns2.p02.nsone.net.
dns3.p02.nsone.net.
dns4.p02.nsone.net.
MX1 aspmx.l.google.com.
10 alt3.aspmx.l.google.com.
10 alt4.aspmx.l.google.com.
10 mail.jons.nl.
5 alt1.aspmx.l.google.com.
5 alt2.aspmx.l.google.com.
SOAdns1.p02.nsone.net. hostmaster.nsone.net. 1663101698 43200 7200 1209600 3600
Mail authentication
SPF2 SPF records (RFC violation)Fail
DMARCmissingFail
DKIMnot detected on common selectors-
DNSSEC
ZoneOff
IP intelligence
Primary IP198.185.159.145
TLS certificate
CertificateLet's Encrypt · expires 2026-11-27 (88d)Valid
HTTP security headers
HTTPS redirectYes
HSTSYes
CSPNo
X-Content-TypeNo
X-Frame-OptionsNo
Referrer-PolicyNo
Permissions-PolicyNo
ServerSquarespace