Domain Email Security & BIMI Inspector
Verify your domain's email authentication chain in 1 click. Check DMARC compliance for BIMI, MTA-STS strict transport encryption, SMTP TLS reporting, and SPF anti-spoofing.
✅ DMARC & BIMI Policy
Evaluates whether your policy qualifies for BIMI avatars (p=quarantine pct=100 or p=reject) and prevents email spoofing.
🟣 BIMI DNS & Logo Probe
Finds default._bimi records, verifies HTTPS reachability, checks content types and SVG Tiny 1.2 profile conformance.
🔒 MTA-STS Strict Transport (RFC 8461)
Checks for DNS records and queries https://mta-sts.domain/.well-known/mta-sts.txt to enforce TLS delivery.
📊 SMTP TLS-RPT (RFC 8460)
Validates aggregate SMTP TLS reporting records so you receive diagnostic telemetry on delivery failures.
Frequently Asked Questions about Email Deliverability
What DMARC policy is required for BIMI avatars?
BIMI requires an active DMARC policy of at least p=quarantine with pct=100 or p=reject. A policy of p=none is considered observation-only and does not qualify for BIMI logo display.
What is MTA-STS (RFC 8461) and why is it important?
Mail Transfer Agent Strict Transport Security (MTA-STS) prevents man-in-the-middle downgrade attacks on SMTP connections by declaring that sending mail servers must use TLS with trusted certificates.
How does SMTP TLS-RPT (RFC 8460) help?
TLS Reporting enables sending mail providers to send daily aggregate telemetry reports whenever encryption negotiation fails, identifying routing issues and certificate expiration before mail drops.