All Security Checks
Every incoming email runs through these checks automatically. Each one is explained individually — what it does, how to read the result and what to do when it fails.
Authentication
Who may send on behalf of your domain — and can it be proven?
SPF Check DNS + IP
Validates your domain's SPF TXT record and whether the sending server is authorized — including a full audit of the record against RFC 7208.
SPF IP Analysis DNS + BL
Why every IP in your SPF record matters — the report resolves them all recursively and checks each for blacklist entries, reverse DNS, FCrDNS and ASN ownership.
DKIM Check CRYPTO
How DKIM signs outgoing mail — the report verifies every signature in the message against the key in DNS and checks alignment with the From header.
DMARC Check DNS + POLICY
Validates the DMARC record, evaluates SPF and DKIM alignment, and audits the policy for weaknesses — from p=none through pct to the subdomain policy.
ARC Chain Validation FORWARDING
How ARC carries authentication across forwarding, where SPF fails by design — the report evaluates the Authenticated Received Chain per RFC 8617.
Envelope-From vs Header-From SPOOFING
Why every email has two senders — the report compares the Return-Path address with the visible From header. A mismatch breaks SPF alignment.
SPF Lookup Limit 10 LOOKUPS
How the ten-lookup limit is counted — the report counts your SPF record's DNS lookups recursively across every include and redirect chain, with the sublimits for void lookups, mx and ptr.
DKIM Key Strength RSA/ED25519
Why a passing signature is not necessarily a good one — the report breaks the DKIM signature down into selector, algorithm, key length, signed headers and the l= tag.
DMARC Report Destinations RUA + RUF
Why DMARC reports sent to an external domain need authorization via a _report._dmarc record — the report checks this for every external rua and ruf destination.
Transport Security
Encryption on the way from server to server.
TLS Transport Analysis ENCRYPTION
How TLS protects email in transit — the report reads TLS version, cipher suite and key strength from the Received headers and shows the status per hop.
MTA-STS Check DNS + HTTPS
How MTA-STS enforces TLS for inbound mail with a DNS record and a policy file — and what the report evaluates on mode, MX patterns and validity period.
DANE / TLSA DNSSEC
How DANE anchors a mail server's certificate in DNS via DNSSEC — the report checks the TLSA records of the sender domain's MX hosts.
MX TLS Certificate STARTTLS
What matters in a mail server's TLS certificate — the report opens a real STARTTLS connection to the sender domain's MX servers and inspects the certificate from chain to expiry.
STARTTLS Support SMTP
How STARTTLS upgrades an SMTP connection to encryption — the report connects to the sender domain's MX servers and checks whether STARTTLS is offered in the EHLO response.
TLS-RPT Check REPORTING
How TLS-RPT reports failed encrypted deliveries to you — the report checks the record at _smtp._tls and the reporting address behind it.
Reputation & Blacklists
How your IP, domain and links stand with the major filter lists.
IP Blacklist Check 43 LISTEN
Checks the sending IP against 43 DNS blacklists in parallel — from Spamhaus ZEN to SpamCop and SpamRATS — and shows the return codes of every listing.
Domain Blacklist Check 15 LISTEN
Checks the sender domain against 15 domain-based blacklists. Domain reputation applies independently of the sending IP.
URL Blacklist Check 5 LISTEN
How spam filters rate links — the report extracts the domains of all links in the email body and checks them against URI blacklists.
Homograph / IDN Detection PHISHING
Detects domains with mixed scripts and confusable characters in the sender and links — the technique behind IDN homograph phishing.
DNSBL Return Codes RETURN CODES
Evaluates the A record returned by each blacklist and separates genuine listings from informational codes and rejected queries.
ASN and Network Owner NETWORK
Who owns the sending IP and why it matters — the report resolves AS number, operator, country and registry for every IP, the sending IP as well as each in the SPF record.
Bulk Sender Checklist GMAIL/YAHOO
Turns the requirements Gmail, Yahoo and Microsoft place on bulk senders into a checklist and checks every point that can be read from a single delivered message.
Content & Attachments
What spam filters evaluate in the message body and attachments.
Attachment Analysis MALWARE
Which attachments carry malware — the report detects dangerous file types, double extensions and macro-enabled Office documents.
Body & Spam Analysis SPAM
What spam filters actually score in the message body — the report looks for missing plaintext, tracking pixels, hidden text, shorteners and the image-to-text ratio.
Link Verification HTTP
Why links in email break so often — the report calls every link in the message body and reports dead links, redirect chains, status codes and SSL errors.
Header Analysis METADATA
What an email's headers reveal — the report checks them SpamAssassin-style: Message-ID, date, MIME-Version, Reply-To mismatch, duplicate From headers, X-Mailer and subject.
Reading Received Headers ROUTING
Breaks the Received chain into individual hops with timestamp, server name and encryption status, and derives the actually sending IP address from it.
MIME Structure STRUCTURE
How an email is put together — the report breaks down its MIME structure: content type, which parts exist, the order of text and HTML, and the text-to-image ratio.
List-Unsubscribe & One-Click RFC 8058
When one-click unsubscribe per RFC 8058 applies — the report checks a real message's unsubscribe addresses, the Post header and whether a valid DKIM signature covers both headers.
Phishing Indicators INDICATORS
Looks for the traits phishing mail uses to disguise its sender and link targets: in the display name, the reply address and the links. Indicators, not proof.
DNS & Infrastructure
MX records, reverse DNS and the basics of server reputation.
MX Record Analysis DNS
Resolves the domain's MX records and analyzes each MX host individually — A records, reverse DNS and FCrDNS.
HELO / rDNS Match SMTP
How receivers match the HELO/EHLO hostname against the sending IP's reverse DNS. A mismatch is one of the most common rejection reasons at large providers.
BIMI Check BRANDING
How BIMI puts your brand logo in the inbox — the report shows whether a BIMI record exists and which logo URL it names. It requires an enforced DMARC policy.
FCrDNS Check PTR + A
Resolves an IP's PTR record, looks the resulting hostname up again in the forward direction and checks whether the original IP comes back.
Test your own configuration
Send any email to hello@analyzemy.email and within seconds you get back a complete report covering every check described here.
Analyze your email now