6things to fix
✗No DMARC record - domain is open to spoofing.▸
Publish a TXT record at _dmarc starting with v=DMARC1; p=none; rua=mailto:you@yourdomain, then tighten it to reject once senders pass.
Read the guide →!No IPv6 (AAAA) record.▸
Add an AAAA record with your server's IPv6 address, or switch on IPv6 at your host or CDN (on Cloudflare it's on by default for proxied records).
!No SPF record for a mail-enabled domain.▸
Publish one SPF TXT record listing your senders, e.g. v=spf1 include:_spf.yourprovider.com -all.
Read the guide →!No HSTS header - add Strict-Transport-Security.▸
Send Strict-Transport-Security: max-age=31536000; includeSubDomains on every response, at your server or CDN edge.
Read the guide →!No Content-Security-Policy header.▸
Add a Content-Security-Policy. Start in Content-Security-Policy-Report-Only mode, refine it, then enforce.
Read the guide →!Missing X-Content-Type-Options: nosniff.▸
Add the header X-Content-Type-Options: nosniff to stop browsers MIME-sniffing responses.
Read the guide →DNS records
A188.114.96.0
188.114.97.0
AAAAnone
Nameserversjake.ns.cloudflare.com.
lisa.ns.cloudflare.com.
MX0 mail.valid.mldsa44.dnstest.dev.
SOAjake.ns.cloudflare.com. hostmaster.valid.mldsa44.dnstest.dev. 1 3600 600 1209600 0
Mail authentication
SPFmissingWarn
DMARCmissingFail
DKIMnot detected on common selectors-
DNSSEC
Zone1 DNSKEY record(s)Signed
IP intelligence
Primary IP188.114.96.0
TLS certificate
CertificateGoogle Trust Services · expires 2026-12-08 (78d)Valid
HTTP security headers
HTTPS redirectYes
HSTSNo
CSPNo
X-Content-TypeNo
X-Frame-OptionsNo
Referrer-PolicyNo
Permissions-PolicyNo
Servercloudflare
Add this badge to your site
<a href="https://nattvakt.com/report/valid.mldsa44.dnstest.dev"><img src="https://nattvakt.com/badge/valid.mldsa44.dnstest.dev.svg" alt="Domain health"></a>