Check it right now, free and with no sign-up:
Six public records decide whether a stranger can write in your domain’s name, and whether mail addressed to you travels encrypted. Anyone can read them, you included. Here is what each one does.
Lists the servers allowed to send email for your domain. Without it, any server can claim to be yours. Published without a strict close, it enumerates your legitimate senders without refusing anyone else.
A cryptographic signature your sending provider adds to every message, verifiable with a public key you publish on your side. It establishes that the message really comes from your domain and was not altered in transit. The key is published under a selector, a name the provider chooses.
Tells receiving servers what to do with a message that fails SPF and DKIM: let it through, quarantine it, or reject it. It is the only one of the three that refuses anything. A domain whose policy enforces nothing stays spoofable, however good the rest is.
Requires the servers writing to you to use an encrypted connection and to check your certificate. Without it, transport encryption is negotiated in the clear and can be stripped by anyone sitting on the path.
Reports back when an encrypted connection to your servers fails. It protects nothing on its own: it is what lets you see that MTA-STS is not working.
Shows your logo next to your messages in the inboxes that support it. It requires a DMARC policy that already enforces, so it comes last and never first.
No. It reads what your domain publishes publicly, which is what any mail server does before writing to you. No message is sent and no mailbox is touched.
Neither. You enter a domain, you get the result. No address is asked of you to see it.
Because DMARC is the only checked record that refuses anything. As long as your policy enforces nothing, a spoofed message goes through despite a flawless SPF and DKIM. So the letter stays below the score until the policy enforces.
With no MX record, the domain does not receive mail and email authentication does not apply to it: there is nothing to grade, and this is not a bad result. If you send email from another domain, check that one.
It means at least one record could not be read. A grade calculated without it would be wrong: an unread SPF record alone is worth a whole letter. We would rather tell you what we did not see. Run it again in a few minutes, these failures are almost always temporary.
No, and nobody can state that on your behalf. Email authentication is one of the external security measures an organization is expected to maintain under Law 25, and this page shows you where you stand on that specific point. CyberAzimut is not a certification body.
After every change to a tool that sends in your name, and otherwise a few times a year. SPF has a limit of ten DNS lookups: past that, receiving servers treat the record as invalid and it covers nothing. You reach it by adding tools one at a time, with nothing to signal it.
The other half of the question: which names close to yours are already registered. Free typosquatting check