All Security Checks
Infrastructure CheckA05:2021

DNS & Email Security Scanner

Verify DNS configuration, SPF, DKIM, DMARC records, and domain security.

DNS misconfigurations can lead to domain hijacking, email spoofing, and subdomain takeover. Our scanner checks SPF, DKIM, and DMARC records for email authentication, DNS zone configuration, DNSSEC status, and subdomain enumeration for potential takeover risks.

What This Scanner Does

Queries DNS records for SPF, DKIM, DMARC configuration. Checks for dangling CNAME records (subdomain takeover risk), verifies DNSSEC deployment, analyzes nameserver configuration, and validates email authentication records.

Why It Matters

Without proper SPF/DKIM/DMARC, anyone can send emails that appear to come from your domain — enabling phishing attacks against your users. DNS misconfigurations can also let attackers take over your subdomains or redirect your traffic.

Common Findings

  • Missing or misconfigured DMARC policy
  • SPF record too permissive (using +all)
  • No DKIM signing configured
  • Dangling CNAME records vulnerable to takeover

OWASP Top 10 Coverage

A05:2021Security Misconfiguration

Run This Check on Your Site

Get a full security report with AI-powered fix suggestions in 30 seconds. No setup required.

Related Security Checks