Email Security Posture
Reads a domain’s SPF, DKIM, DMARC, MX and DNSSEC records straight off the graph and grades each on presence and hygiene: whether the control is configured, whether the SPF chain stays inside the ten-lookup limit, whether an SPF_IP authorization is unusually wide, whether a DKIM signer has no matching SPF authorization, and whether a mail-exchange address carries a threat verdict. Never grades enforcement strength — SPF’s -all qualifier and DMARC’s p= policy tag are not yet imported into the graph (whisper-dbj-ng#1865).
This is the reference page: what each step asks the graph, and why. Run it on the DNS & email security use-case page.
On this page (4)
What it solves
A domain that sends mail without SPF, DKIM or DMARC configured is trivially spoofable, and a domain that signs mail with DKIM but never set up DMARC reporting has no way to find out when someone else does. Checking all four controls by hand means separately dumping SPF mechanisms, DKIM signers, DMARC recipients and MX records and cross-referencing them — and RFC 7208’s ten-DNS-lookup SPF limit is easy to blow past without noticing.
Why
- 01Mail-exchange hosts. MAIL_FOR names the servers this domain’s mail actually routes through.
- 02Mail-exchange provider. Names who actually operates the mail path, not just its hostnames.
- 03Mail-exchange carrier network. The network that actually carries this domain’s mail, one hop past the hostname.
- 04Mail-exchange threat check. A coverage-qualified suspicion band, so no-data never reads as clean.
- 05SPF mechanisms. Each mechanism type dumped once, undecoded — the record’s own shape, not a re-parse of the TXT string.
- 06SPF include chain. A wide or deep include chain burns the ten-lookup RFC 7208 limit before enforcement even applies.
- 07SPF authorized address space. A single SPF_IP mechanism naming a wide range authorizes far more senders than the record’s own line count suggests.
- 08DKIM signers. A DKIM signer names the platform actually authorized to send as this domain.
- 09DMARC report recipients. An empty recipient list beside a populated signer list means mail goes out under the domain and nobody collects the reports.
- 10Registrable apex. The apex a DMARC recipient’s own domain is compared against to call it external.
- 11DNSSEC signing. Checking DNSSEC signing…
What this cost
11 named steps across the DNS, email, BGP layers. The runner reports what each step returned, row by row, so the evidence and what it took to get it arrive together rather than as one number at the end.
How it uses the graph
Traverses the DNS, email, BGP layers of the graph, in 11 steps:
Reading the mail-exchange hosts…
Identifying the mail-exchange provider…
Resolving the mail-exchange carrier network…
Checking the mail-exchange addresses against the threat feeds…
Reading every SPF mechanism…
Following the SPF include chain…
Sizing the SPF-authorized address space…
Reading who signs this domain’s mail…
Reading who receives this domain’s DMARC aggregate reports…
Resolving the registrable apex…
Checking DNSSEC signing…