nzherald.co.nz
Live email deliverability and anti-spoofing audit. Every value below was read from public DNS at the moment this page was generated.
86/100 — Solid configuration with a few gaps worth closing. Accepts mail · Protected against spoofing · Hosted by Mimecast
Findings
-
dkim
No DKIM key found at any common selector. Either DKIM is not configured, or it uses a custom selector we cannot discover from DNS alone.
Fix: Enable DKIM signing at your mail provider and publish the selector they give you.
-
mta sts
No MTA-STS policy, so inbound mail can be downgraded to an unencrypted connection.
Fix: Publish _mta-sts.nzherald.co.nz and host a policy at https://mta-sts.nzherald.co.nz/.well-known/mta-sts.txt.
-
mx
Mail is handled by Mimecast.
10 au-smtp-inbound-1.mimecast.com, 10 au-smtp-inbound-2.mimecast.com
-
spf
SPF is published and enforcing.
v=spf1 include:au._netblocks.mimecast.com include:spf.protection.outlook.com include:_spf.google.com include:servers.mcsv.net -all
-
dmarc
DMARC is enforcing with p=reject.
v=DMARC1; p=reject; sp=reject; rua=mailto:87593a3ca9e7167@rep.dmarcanalyzer.com; ruf=mailto:87593a3ca9e7167@for.dmarcanalyzer.com; fo=1;
Records
| MX | 10 au-smtp-inbound-1.mimecast.com10 au-smtp-inbound-2.mimecast.com |
|---|---|
| SPF | v=spf1 include:au._netblocks.mimecast.com include:spf.protection.outlook.com include:_spf.google.com include:servers.mcsv.net -all |
| DMARC | v=DMARC1; p=reject; sp=reject; rua=mailto:87593a3ca9e7167@rep.dmarcanalyzer.com; ruf=mailto:87593a3ca9e7167@for.dmarcanalyzer.com; fo=1; |
| DKIM selectors | none discovered |
| MTA-STS | not published |
| TLS-RPT | not published |
| BIMI | not published |
| DNSSEC | not validating |
Same data, as JSON, in one request. No SMTP probing, no stored recipient data, 250 free calls a month.
curl "https://mailgrade.dev/v1/domain?domain=nzherald.co.nz"
Also available: /v1/verify?email=… for individual addresses, and
/v1/verify/batch for lists.