Skip to content
Workflows
Skip navigation
Workflows
View as Markdown

Email Security Posture

Reads a domain’s SPF, DKIM, DMARC, MX and DNSSEC records straight off the graph and grades each on presence and hygiene: whether the control is configured, whether the SPF chain stays inside the ten-lookup limit, whether an SPF_IP authorization is unusually wide, whether a DKIM signer has no matching SPF authorization, and whether a mail-exchange address carries a threat verdict. Never grades enforcement strength — SPF’s -all qualifier and DMARC’s p= policy tag are not yet imported into the graph (whisper-dbj-ng#1865).

Published

This is the reference page: what each step asks the graph, and why. Run it on the DNS & email security use-case page.

On this page (4)

What it solves

A domain that sends mail without SPF, DKIM or DMARC configured is trivially spoofable, and a domain that signs mail with DKIM but never set up DMARC reporting has no way to find out when someone else does. Checking all four controls by hand means separately dumping SPF mechanisms, DKIM signers, DMARC recipients and MX records and cross-referencing them — and RFC 7208’s ten-DNS-lookup SPF limit is easy to blow past without noticing.

Why

  1. 01Mail-exchange hosts. MAIL_FOR names the servers this domain’s mail actually routes through.
  2. 02Mail-exchange provider. Names who actually operates the mail path, not just its hostnames.
  3. 03Mail-exchange carrier network. The network that actually carries this domain’s mail, one hop past the hostname.
  4. 04Mail-exchange threat check. A coverage-qualified suspicion band, so no-data never reads as clean.
  5. 05SPF mechanisms. Each mechanism type dumped once, undecoded — the record’s own shape, not a re-parse of the TXT string.
  6. 06SPF include chain. A wide or deep include chain burns the ten-lookup RFC 7208 limit before enforcement even applies.
  7. 07SPF authorized address space. A single SPF_IP mechanism naming a wide range authorizes far more senders than the record’s own line count suggests.
  8. 08DKIM signers. A DKIM signer names the platform actually authorized to send as this domain.
  9. 09DMARC report recipients. An empty recipient list beside a populated signer list means mail goes out under the domain and nobody collects the reports.
  10. 10Registrable apex. The apex a DMARC recipient’s own domain is compared against to call it external.
  11. 11DNSSEC signing. Checking DNSSEC signing…

What this cost

11 named steps across the DNS, email, BGP layers. The runner reports what each step returned, row by row, so the evidence and what it took to get it arrive together rather than as one number at the end.

How it uses the graph

Traverses the DNS, email, BGP layers of the graph, in 11 steps:

How it walks the graph11 steps
01Mail-exchange hosts

Reading the mail-exchange hosts…

DNSemailBGP
02Mail-exchange provider

Identifying the mail-exchange provider…

DNSemailBGP
03Mail-exchange carrier network

Resolving the mail-exchange carrier network…

DNSemailBGP
04Mail-exchange threat check

Checking the mail-exchange addresses against the threat feeds…

DNSemailBGP
05SPF mechanisms

Reading every SPF mechanism…

DNSemailBGP
06SPF include chain

Following the SPF include chain…

DNSemailBGP
07SPF authorized address space

Sizing the SPF-authorized address space…

DNSemailBGP
08DKIM signers

Reading who signs this domain’s mail…

DNSemailBGP
09DMARC report recipients

Reading who receives this domain’s DMARC aggregate reports…

DNSemailBGP
10Registrable apex

Resolving the registrable apex…

DNSemailBGP
11DNSSEC signing

Checking DNSSEC signing…

DNSemailBGP