The records behind the domain.
Email, DNS, transport and the infrastructure under them are the four sets below, and an entry gives the published configuration together with the requirement it was checked against.
Frontend demo. This searches the sample entries on this page. The full index ships with the knowledge base.
Browse
Four categories.
The number on the card is how many entries are in that set.
Email authentication
SPF, DKIM and DMARC. What the record signs, and what a receiver checks when it fails.
94 entries
DNS security
DNSSEC, CAA and record hygiene. The delegation failures an attacker uses first.
67 entries
Transport security
STARTTLS, MTA-STS and TLS-RPT. How mail stays encrypted in transit, and where that encryption drops without an error.
41 entries
Infrastructure
Hosting, senders and resolvers. What every record and policy sits on.
58 entries
Popular
Open these first.
DMARC, the SPF record, SPF PermError, DNSSEC, the DKIM selector. Most of what breaks on a domain starts here.
Changelog
What moved.
Sender rules and protocol requirements change. The entry is rewritten, and the row is the diff.
Methodology
Kept current.
When a sender or a standard changes a rule, the entry is rewritten. The changelog lists those rewrites.
- Every entry has an owner
- Every entry names a source
- Every entry carries a last-verified date