Nothing is broken, but 1 of 8 checks needs attention. Start with MTA-STS.
The DNS record is published, but the policy file at mta-sts.readinessnavigator.com can't be loaded, so senders ignore it.
We couldn't complete this lookup just now, so it isn't counted in your score. Try the check again in a minute.
Microsoft 365 detected and correctly configured. Your mail arrives where it should.readinessnavigator-com.mail.protection.outlook.com
Forged mail in your name is rejected.v=DMARC1; pct=100; p=reject; rua=mailto:dmarc_agg@vali.email;
Your list of allowed senders is published and strictly enforced.v=spf1 include:spf.protection.outlook.com -all
1 of the 10 permitted lookups used. Room left for further services.
Your outgoing mail is signed, so receivers can verify it really came from you.selectors: selector1, selector2
You receive a report when another server has trouble delivering mail to you securely.v=TLSRPTv1; rua=mailto:tls-reports@readinessnavigator.com
Your domain's records are signed, so visitors can't be quietly redirected to a forged address.
Checked live against public DNS. Rows marked “not tested” or “not applicable” are left out of the score. We never need access to your systems to run this.
All 1 open item is covered by our Essential package. You get a quote with a fixed price and a fixed date before anything starts.