Nothing is broken, but 3 of 9 checks need attention. Start with MTA-STS.
Not configured. The encryption on mail sent to you can be stripped away in transit without anyone noticing.
Not configured. If mail to you fails to arrive securely, nobody tells you.
Not active. Your domain is open to visitors being redirected to a forged address. Your registrar can usually switch this on in minutes.
Microsoft 365 detected and correctly configured. Your mail arrives where it should.leonisresilience-com.mail.protection.outlook.com
Forged mail in your name is rejected.v=DMARC1; p=reject; pct=100; rua=mailto:dmarc_agg@vali.email;ruf=mailto:dmarc_agg@vali.email;
Your list of allowed senders is published and strictly enforced.v=spf1 include:spf.protection.outlook.com -all
1 of the 10 permitted lookups used. Room left for further services.
Your outgoing mail is signed, so receivers can verify it really came from you.selectors: selector1, selector2
Your website loads securely over HTTPS with a valid certificate.leonisresilience.com
Checked live against public DNS. Rows marked “not tested” or “not applicable” are left out of the score. We never need access to your systems to run this.
All 3 open items are covered by our Essential package. You get a quote with a fixed price and a fixed date before anything starts.