5things to fix
✗No DMARC record - domain is open to spoofing.▸
Publish a TXT record at _dmarc starting with v=DMARC1; p=none; rua=mailto:you@yourdomain, then tighten it to reject once senders pass.
Read the guide →!No SPF record for a mail-enabled domain.▸
Publish one SPF TXT record listing your senders, e.g. v=spf1 include:_spf.yourprovider.com -all.
Read the guide →!No HSTS header - add Strict-Transport-Security.▸
Send Strict-Transport-Security: max-age=31536000; includeSubDomains on every response, at your server or CDN edge.
Read the guide →!No Content-Security-Policy header.▸
Add a Content-Security-Policy. Start in Content-Security-Policy-Report-Only mode, refine it, then enforce.
Read the guide →!Missing X-Content-Type-Options: nosniff.▸
Add the header X-Content-Type-Options: nosniff to stop browsers MIME-sniffing responses.
Read the guide →DNS records
A188.114.96.0
188.114.97.0
AAAA2a06:98c1:3120::
2a06:98c1:3121::
Nameserversjake.ns.cloudflare.com.
lisa.ns.cloudflare.com.
MX0 mail.valid.mldsa44.dnstest.dev.
SOAjake.ns.cloudflare.com. hostmaster.valid.mldsa44.dnstest.dev. 1 3600 600 1209600 0
Mail authentication
SPFmissingWarn
DMARCmissingFail
DKIMnot detected on common selectors-
DNSSEC
Zone1 DNSKEY record(s)Signed
IP intelligence
Primary IP188.114.96.0
TLS certificate
CertificateGoogle Trust Services · expires 2026-12-08 (78d)Valid
HTTP security headers
HTTPS redirectYes
HSTSNo
CSPNo
X-Content-TypeNo
X-Frame-OptionsNo
Referrer-PolicyNo
Permissions-PolicyNo
Servercloudflare
Add this badge to your site
<a href="https://nattvakt.com/report/valid.mldsa44.dnstest.dev"><img src="https://nattvakt.com/badge/valid.mldsa44.dnstest.dev.svg" alt="Domain health"></a>