What it checks
Email spoofing
Whether someone else can send email that appears to come from your domain.
How it is checked
Sentinel looks up the public DNS records that tell mail providers which senders are really you.
- Email sender records. The SPF, DKIM and DMARC records on your domain.
What it can find
Anyone can send email that claims to be from your domain
Should fixMakes an attack easier or more damaging.
- What it is
- Your domain has no SPF record, the public list of which servers are allowed to send your email.
- Why it matters
- Mail providers have no way to tell real email from you apart from a forgery, so forged invoices and password requests in your name are more likely to be delivered. Your real email is also more likely to land in spam.
- How to fix it
- Add a TXT record to the domain's DNS listing the services that send your email. Your email provider's help pages give the exact value.
Your list of allowed email senders does not block anyone
Worth tidyingGood practice that is missing.
- What it is
- Your domain has an SPF record, but the way it ends tells mail providers to accept email from servers that are not on the list.
- Why it matters
- The record is there but does not stop forgeries.
- How to fix it
- Change the end of the SPF record to ~all, or -all once you are sure every real sender is listed.
Mail providers are not told what to do with forged email from your domain
Should fixMakes an attack easier or more damaging.
- What it is
- Your domain has no DMARC record, the instruction that tells mail providers to reject or quarantine email that fails your checks.
- Why it matters
- Without it, forged email in your name is usually delivered anyway. Some large mail providers now require it from anyone who sends in bulk.
- How to fix it
- Add a TXT record named _dmarc to the domain's DNS. Start with v=DMARC1; p=none; rua=mailto:an address you read, watch the reports, then tighten it.
Forged email from your domain is watched but not blocked
Worth tidyingGood practice that is missing.
- What it is
- Your DMARC record is set to p=none, which asks mail providers to report forgeries but deliver them anyway.
- Why it matters
- It is the right first step, but it gives no protection until it is tightened.
- How to fix it
- Change p=none to p=quarantine, and later p=reject, after checking the reports show your real email passing.
No email signing key was found for your domain
Worth tidyingGood practice that is missing.
- What it is
- Sentinel looked for a DKIM key under the names most mail providers use and found none. DKIM lets a mail provider confirm an email really came from you and was not changed.
- Why it matters
- Without signing, your email is more likely to be treated as spam, and DMARC has less to work with.
- How to fix it
- Turn on DKIM in your email provider's settings and add the DNS record it gives you. If your provider uses an unusual key name, DKIM may be working and you can accept this finding.