Skip to content
SAMPLE REPORTSample report

Status summary

Evidence for awesome-store.com

This page stays focused on observable email-authentication evidence: what the scan found, which records are blocking readiness, and the exact changes InboxGreen would publish next.

Domain
awesome-store.com
Checked
January 15, 2025 at 3:00 PM
Evidence basis
Public DNS and sender-policy checks only

Mailbox readiness

54/100

Medium-High risk

Key records need attention before Gmail/Yahoo enforcement. Action required before this domain is mailbox-ready.

Critical blockers1
Supporting issues5
Passing controls2

Key findings

  1. 01

    SPF record exceeds lookup limit (12/10)

  2. 02

    DMARC policy missing

  3. 03

    DKIM selectors not configured for Mailgun

  4. 04

    TLS reporting mailbox missing

Report note

This hierarchy is intentionally evidence-first. It shows observed control state, concrete DNS artifacts, and the next managed action instead of wrapping the scan in dashboard chrome.

What Wave 2 should inherit

  • Lead with readiness and evidence, not charts or growth framing.
  • Use IBM Plex Mono only for records, timestamps, and policy snippets.
  • Reserve green for ready or verified states; use blue for diagnostic context.

DNS and report artifacts

Observed controls

Each control below shows current observed state, the evidence the scan can point to, and the managed action InboxGreen would take next.

Needs work

SPF Record

SPF record uses 12 DNS lookups (limit is 10)

Observed evidence

Current value

v=spf1 include:_spf.google.com include:sendgrid.net include:mailgun.org include:servers.email.com ~all
  • 12 DNS lookups
  • 8 mechanisms

Managed action

Collapse SPF includes under the 10-lookup limit and keep new senders tracked automatically.

Needs work

DKIM

Selectors missing for 2 sending sources

Observed evidence

Current value

s1, s2, custom

Managed action

Publish missing selectors and rotate 2048-bit keys without manual DNS edits.

Blocking

DMARC Policy

DMARC policy missing

Observed evidence

No concrete record value surfaced in the sample payload.

Managed action

Publish a monitoring policy first, then stage quarantine and reject once alignment is clean.

Passing

MX Records

Configured correctly

Observed evidence

Current value

aspmx.l.google.com, alt1.aspmx.l.google.com

Managed action

Keep delivery endpoints monitored so drift is detected before mailbox routing breaks.

Passing

HTTPS

Configured correctly

Observed evidence

Current value

HSTS not enforced

Managed action

Keep the web posture documented, but this is not the current deliverability blocker.

Blocking

MTA-STS

No MTA-STS policy published

Observed evidence

No concrete record value surfaced in the sample payload.

Managed action

Host the policy and re-validate it continuously so inbound TLS policy does not lapse.

Needs work

TLS Reporting

No TLS reporting destination configured

Observed evidence

No concrete record value surfaced in the sample payload.

Managed action

Provision a reporting address and parse failures so transport issues surface quickly.

Needs work

security.txt

security.txt endpoint missing

Observed evidence

No concrete record value surfaced in the sample payload.

Managed action

Publish a contactable security.txt endpoint so external findings have a valid disclosure path.

DNS record evidence

Current records stay visible next to the target state so report readers can compare proof and managed output without switching context.

Diagnostic comparison
TXTNeeds work

awesome-store.com

SPF record uses 12 DNS lookups (limit is 10)

12 lookups

Current record

awesome-store.com

v=spf1 include:_spf.google.com include:sendgrid.net include:mailgun.org include:servers.email.com ~all

InboxGreen target

awesome-store.com

v=spf1 include:_spf.inboxgreen.com ~all

Optimized SPF served via InboxGreen

TXTBlocking

_dmarc.awesome-store.com

DMARC policy missing

Current record

_dmarc.awesome-store.com

No DMARC record

InboxGreen target

_dmarc.awesome-store.com

v=DMARC1; p=none; rua=mailto:dmarc@awesome-store.com

Gradual enforcement plan

TXTNeeds work

DKIM selectors

Selectors missing for 2 sending sources

Current record

DKIM selectors

s1, s2, custom

InboxGreen target

DKIM selectors

selector1, selector2, selector3

2048-bit keys rotated automatically

TXTBlocking

_mta-sts.awesome-store.com

No MTA-STS policy published

Current record

_mta-sts.awesome-store.com

Policy not published

InboxGreen target

_mta-sts.awesome-store.com

version: STSv1, mode: enforce, max_age: 86400

InboxGreen hosts and manages policy

TXTNeeds work

_smtp._tls.awesome-store.com

No TLS reporting destination configured

Current record

_smtp._tls.awesome-store.com

No TLSRPT destination

InboxGreen target

_smtp._tls.awesome-store.com

v=TLSRPTv1; rua=mailto:tlsrpt@awesome-store.com

TLS reports monitored in dashboard

TXTNeeds work

security.txt

security.txt endpoint missing

Current record

security.txt

Missing

InboxGreen target

security.txt

https://awesome-store.com/.well-known/security.txt

InboxGreen publishes contacts + policies

Next action

Move from evidence to managed change

Start the managed fix plan so SPF, DMARC, and any missing selectors are published safely.

  1. 0 min

    Verify domain ownership

    Confirm awesome-store.com so we can publish records safely

  2. 2 min

    Connect providers

    Securely link Gmail, Microsoft 365, SendGrid, etc.

  3. 5 min

    Optimize SPF

    SPF record uses 12 DNS lookups (limit is 10)

  4. 8 min

    Stage DMARC enforcement

    DMARC policy missing

  5. 10 min

    Deploy DKIM selectors

    Selectors missing for 2 sending sources

Managed fix plan

InboxGreen publishes the records, waits for propagation, and keeps monitoring active.

Elapsed time note

Most elapsed time is DNS propagation. The operator work here is verifying ownership, approving changes, and letting the records settle.