Email Security Analyzer
Email Security Diagnostic
Domain
Authentication
Transport
Reporting
Brand
This tool inspects publicly visible DNS records and policy files only — it does not require or accept Microsoft 365, Google Workspace, or mailbox credentials, and it never connects to mail servers or sends email. IT KORR's own domains and infrastructure cannot be scanned with this tool.
What This Tool Checks
Seven Areas of Email Domain Security
Grouped into four scored categories — Authentication, Transport Security, Reporting & Visibility, and Brand Authentication.
MX Records
Inbound mail routing configuration and priority ordering.
SPF
Which mail servers are authorized to send on this domain's behalf.
DKIM
Cryptographic signing, checked against common provider selectors.
DMARC
Enforcement policy, percentage applied, and aggregate reporting.
BIMI
Published brand logo and Verified Mark Certificate authority, if any.
MTA-STS
Transport security policy requiring TLS for inbound mail delivery.
TLS-RPT
Visibility into TLS delivery failures via aggregate reports.
Understanding Your Score
External Configuration Only, Not a Complete Security Rating
This score reflects only the externally visible DNS records and policy files this tool checks. It does not assess mailbox-level protections, user awareness training, inbound spam filtering, or anything requiring authentication to your email platform — treat it as one input into a broader email security review, not a complete verdict.
FAQ
Common Questions
How is this different from the SPF / DKIM / DMARC Checker?
The SPF / DKIM / DMARC Checker is a focused email-authentication check. This analyzer covers the same authentication ground plus a broader domain-level email security posture — MX configuration, BIMI brand authentication, MTA-STS transport security, and TLS-RPT delivery reporting — with a category-weighted score across all of it.
Does this tool need my Microsoft 365 or Google Workspace login?
No. This is an external DNS and policy inspection only — it never requests or accepts mailbox, tenant, or admin credentials of any kind, and it never connects to your mail servers or sends email.
What does "no DKIM record found" actually mean?
DKIM discovery is selector-dependent — this tool checks a list of common provider selectors (shown in your results) via DNS. A record not being found on any of them does not prove DKIM is not configured; a non-standard selector may be in use. Confirm your actual selector with your email provider if this result surprises you.
Is p=none in DMARC automatically a problem?
No. p=none is a legitimate monitoring-only starting posture, not a broken configuration — it lets you review aggregate reports before enforcing quarantine or reject. It scores lower than an enforced policy because it provides no filtering protection yet, but it is an expected and reasonable first step.
Does a BIMI record guarantee my logo will show up in recipients' inboxes?
No. Mailbox provider support varies, and many providers require a Verified Mark Certificate (VMC) in addition to a valid BIMI record and DMARC enforcement. This tool confirms the record and its published fields, not whether your logo actually renders for every recipient.
Does this tool test my SMTP server directly?
No. This is DNS and policy-file inspection only. It does not open SMTP connections, grab server banners, attempt mailbox enumeration, test for open relays, or send any email.
Related Tools & Services
Need a focused authentication check? Get deeper analysis of SPF, DKIM, and DMARC alone.
Full DNS diagnostic including MX routing and nameserver records.
Inspect certificate validity, expiration, and TLS version for any domain.
Ongoing email authentication and Defender configuration management.
Operational Support
Need help closing your email security gaps?
IT KORR can implement SPF, DKIM, DMARC enforcement, MTA-STS, and BIMI as part of ongoing Microsoft 365 or email platform management.
No commitment required — we respond within one business day.