# Email Security Posture

> Reads a domain’s SPF, DKIM, DMARC, MX and DNSSEC records straight off the graph and grades each on presence and hygiene: whether the control is configured, whether the SPF chain stays inside the ten-lookup limit, whether an SPF_IP authorization is unusually wide, whether a DKIM signer has no matching SPF authorization, and whether a mail-exchange address carries a threat verdict. Never grades enforcement strength — SPF’s -all qualifier and DMARC’s p= policy tag are not yet imported into the graph (whisper-dbj-ng#1865).

*Source: https://www.whisper.security/docs/workflows/email-security-posture*

---
## What it solves

A domain that sends mail without SPF, DKIM or DMARC configured is trivially spoofable, and a domain that signs mail with DKIM but never set up DMARC reporting has no way to find out when someone else does. Checking all four controls by hand means separately dumping SPF mechanisms, DKIM signers, DMARC recipients and MX records and cross-referencing them — and RFC 7208’s ten-DNS-lookup SPF limit is easy to blow past without noticing.

## How it uses the graph

Traverses the DNS, email, BGP layers of the graph, in 11 steps:

01. **Mail-exchange hosts** _(DNS, email, BGP)_ — Reading the mail-exchange hosts…
02. **Mail-exchange provider** _(DNS, email, BGP)_ — Identifying the mail-exchange provider…
03. **Mail-exchange carrier network** _(DNS, email, BGP)_ — Resolving the mail-exchange carrier network…
04. **Mail-exchange threat check** _(DNS, email, BGP)_ — Checking the mail-exchange addresses against the threat feeds…
05. **SPF mechanisms** _(DNS, email, BGP)_ — Reading every SPF mechanism…
06. **SPF include chain** _(DNS, email, BGP)_ — Following the SPF include chain…
07. **SPF authorized address space** _(DNS, email, BGP)_ — Sizing the SPF-authorized address space…
08. **DKIM signers** _(DNS, email, BGP)_ — Reading who signs this domain’s mail…
09. **DMARC report recipients** _(DNS, email, BGP)_ — Reading who receives this domain’s DMARC aggregate reports…
10. **Registrable apex** _(DNS, email, BGP)_ — Resolving the registrable apex…
11. **DNSSEC signing** _(DNS, email, BGP)_ — Checking DNSSEC signing…

## Why each step runs

1. **Mail-exchange hosts.** MAIL_FOR names the servers this domain’s mail actually routes through.
2. **Mail-exchange provider.** Names who actually operates the mail path, not just its hostnames.
3. **Mail-exchange carrier network.** The network that actually carries this domain’s mail, one hop past the hostname.
4. **Mail-exchange threat check.** A coverage-qualified suspicion band, so no-data never reads as clean.
5. **SPF mechanisms.** Each mechanism type dumped once, undecoded — the record’s own shape, not a re-parse of the TXT string.
6. **SPF include chain.** A wide or deep include chain burns the ten-lookup RFC 7208 limit before enforcement even applies.
7. **SPF authorized address space.** A single SPF_IP mechanism naming a wide range authorizes far more senders than the record’s own line count suggests.
8. **DKIM signers.** A DKIM signer names the platform actually authorized to send as this domain.
9. **DMARC report recipients.** An empty recipient list beside a populated signer list means mail goes out under the domain and nobody collects the reports.
10. **Registrable apex.** The apex a DMARC recipient’s own domain is compared against to call it external.
11. **DNSSEC signing.** Anchored on the hostname — the reverse walk from the algorithm side is a known engine timeout (whisper-dbj-ng#2320).

[Open the full use-case page, with the live runner](/products/intelligence/use-cases/dns-email-security/email-security-posture)
