SPF authorizes sending infrastructure
SPF publishes which systems are allowed to send mail for a domain. Forwarding and complex mail flows can affect how SPF behaves.
DKIM signs message content and identity
DKIM uses cryptographic signatures so a receiver can verify that signed parts of a message were not altered and that the signing domain takes responsibility for the message.
DMARC connects identity and policy
DMARC evaluates alignment between the visible From domain and SPF/DKIM results, and lets a domain publish policy and reporting preferences.
Public DNS makes these controls observable
Scantide Online can review public SPF and DMARC posture as part of the wider domain assessment. DKIM review depends on knowing or discovering the relevant selector.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: DNS, SPF and DMARC Security CheckerScantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.
Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web ExposureScantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.
Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web ExposureUse Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.
Current Scantide source: Public Server Security AssessmentUse Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.
Current Scantide source: Scantide Online – Domain Security, Privacy and Infrastructure ScannerA single domain can expose signals across DNS, mail, HTTPS, headers and infrastructure. Scantide Online brings those observations into one readable assessment.
Field experience from the archive
Historical source · JufCorp: Securing your servers, users and customers onlineAlso make sure your servers are set correctly in regards to SPF (yep, link in Swedish) and not to accept emails from your own domain from anywhere else than the servers you actually can control and validate.
On the subject of DNS servers. There's absolutely no point in having your DNS servers reachable through the firewall thus enabling attackers to flood it with DNS queries and UDP floods.
Practical review checklist
- Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.
- Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.
- Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.
- Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.
- A single domain can expose signals across DNS, mail, HTTPS, headers and infrastructure.
- Also make sure your servers are set correctly in regards to SPF (yep, link in Swedish) and not to accept emails from your own domain from anywhere else than the servers you actually can control and validate.