Skip to content

Email-domain security

Protecting a domain that sends no email

For a domain with no MX records, whether it declares that it sends no mail with a strict SPF record and a DMARC reject policy.

Part of the External Security Check. Free during the preview.

What it checks

For a domain with no MX records, whether it declares that it sends no mail with a strict SPF record and a DMARC reject policy.

A pass means: The domain either receives mail or declares that it never sends any.

Possible findings

Domain without mail is not protected from spoofing

Severity: LowConfidence: High confidenceKind: Recommended hardening

What we found

The domain receives no mail (no MX records) but does not declare that it sends none.

Why it matters

Domains that never send mail are still used for spoofing. A strict SPF record and DMARC policy tell receivers to reject anything claiming to come from them.

How to fix it

Publish v=spf1 -all, a DMARC record v=DMARC1; p=reject;, and optionally a null MX (0 .).

References