Area: Email
Mail servers, SPF, DMARC, DKIM (common selectors), MTA-STS and TLS-RPT, and the risk of someone sending email pretending to be you. If you receive DMARC reports with Ward, it also flags new senders using your domain and SPF includes that no longer send anything.
What it can report
Open each one to see what it means and how to fix it.
No SPF record
What it means
What could happen
How an attacker would use it
How to fix it
- List every service that sends email as your domain.Your mailbox provider, plus invoicing, newsletters, CRM, online store or website forms.
- Build one SPF record with all of them. It starts with “v=spf1”, adds an “include:” entry for each service and ends with “-all”.Each service's help pages give its exact “include:” entry.
- At your DNS host, add it as a TXT record on the root of the domain (the name “@”).A domain can only have one SPF record. If one already exists, edit it instead of adding another.
- Send a test message to a personal Gmail account and check that it arrives normally.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Duplicate SPF records
What it means
What could happen
How an attacker would use it
How to fix it
- In your DNS settings, find every TXT record that starts with “v=spf1”.
- Write down the services each one lists (the “include:” and “ip4:” entries).
- Create a single record that contains all of them and ends with “-all”.
- Delete the others so only one SPF record is left.Do it in one go: a gap between deleting and saving the new one leaves the domain unprotected.
- Save and send a test message to a personal Gmail account.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
SPF needs too many lookups
What it means
What could happen
How an attacker would use it
How to fix it
- List the services in your SPF (the “include:” entries) and tick the ones you still use.
- Remove the “include:” entries of services you no longer use.Old newsletter tools, previous mailbox providers and former CRMs are common leftovers.
- If you still need more, ask each remaining service whether it has a lighter SPF entry.
- As a last resort, replace a service by its fixed IP addresses (“ip4:”).Only if that service publishes stable addresses. Big providers change theirs without notice.
- Save the change and check that the new record stays within 10 lookups.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
SPF has syntax errors
What it means
What could happen
How an attacker would use it
How to fix it
- Open the technical details and read the mistakes listed under the record.
- Compare the record with your email provider's instructions for SPF.Providers publish the exact “include:” entry to use.
- Correct the record in your DNS settings.Common slips: spaces inside an entry, a missing “v=spf1” at the start, or two “all” endings.
- Make sure it ends with “-all” (or “~all” while you test) and that it is one single TXT record.
- Send a test message to a personal Gmail account and check that it arrives normally.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
SPF points to a list that doesn't exist
What it means
What could happen
How an attacker would use it
How to fix it
- Check the “include:” entries listed in the technical details.
- Ask yourself whether you still use each service. If not, remove its “include:”.
- If you do use it, compare the entry with the service's current instructions.Providers sometimes change the address they publish; an old entry stops working.
- Correct or remove the entry in your DNS settings and save.
- Send a test message to a personal Gmail account and check that it arrives normally.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
SPF allows anyone to send (+all)
What it means
What could happen
How an attacker would use it
How to fix it
- In your DNS settings, open the TXT record that starts with “v=spf1”.
- Check that every service you use is listed with its “include:” or “ip4:” entry.
- Change the ending from “+all” to “-all”.If you aren't sure the list is complete, use “~all” for a few weeks while you check, then move to “-all”.
- Save and send a test message to a personal Gmail account to confirm your own email still arrives.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
SPF doesn't say what to do with fakes
What it means
What could happen
How an attacker would use it
How to fix it
- In your DNS settings, open the TXT record that starts with “v=spf1”.
- Check that all services that send email as your domain are listed.
- End the record with “-all” (reject others) or “~all” (treat others as suspicious).“~all” is gentler. Start with it if you aren't sure the list is complete.
- Save and send a test message to a personal Gmail account to confirm your email still arrives.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
SPF uses the deprecated ptr mechanism
What it means
What could happen
How an attacker would use it
How to fix it
- Open your SPF record in your DNS settings and find the “ptr” entry.
- Work out which service it was meant to cover.Ask your IT person, or check your email provider's SPF instructions.
- Replace “ptr” with the “include:” entry of that service, or with “ip4:” and its fixed address if it has one.
- Save and send a test message to a personal Gmail account to confirm your email still arrives.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
No DMARC policy
What it means
What could happen
How an attacker would use it
How to fix it
- Choose where the reports will go: a mailbox only for this, such as dmarc@example.com, or a DMARC reports service.Reports are daily summaries from Gmail, Outlook and others listing who sent email as your domain. They aren't personal messages.
- At your DNS host, add a TXT record named _dmarc.example.com with the value “v=DMARC1; p=none; rua=mailto:dmarc@example.com”.“p=none” only observes: nothing is blocked yet, so no legitimate email is at risk.
- Read the reports for two to four weeks and list every service that sends as you.In Ward, your domain's “DMARC reports and reputation” page shows the record to copy and, when available, an address that collects the reports for you.
- Make sure each real service passes SPF or DKIM. Fix or authorize those that don't.
- Change “p=none” to “p=quarantine” (suspicious messages go to spam).If a legitimate service starts failing, you'll see it in the reports and can fix it.
- When everything legitimate passes, move to “p=reject” (forged messages are refused).
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
DMARC record can't be used
What it means
What could happen
How an attacker would use it
How to fix it
- Open the TXT records named _dmarc.example.com in your DNS settings.
- Keep a single record that starts with “v=DMARC1;” and includes a “p=” policy, and delete any duplicates.
- If you aren't sure which policy to use, start with “p=none” and an address for reports: “v=DMARC1; p=none; rua=mailto:…”.
- Save the change and wait a few hours for it to spread.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
DMARC only monitors (p=none)
What it means
What could happen
How an attacker would use it
How to fix it
- Read your DMARC reports and list every service that sends email as your domain.In Ward, your domain's “DMARC reports and reputation” page groups senders and tells you when you can tighten your policy.
- Make sure every legitimate service passes SPF or DKIM, and fix or authorize those that don't.
- Change the record named _dmarc.example.com from “p=none” to “p=quarantine”.Suspicious messages will go to spam instead of the inbox.
- Keep reading the reports for a couple of weeks to catch any legitimate sender you missed.
- When everything is clean, change to “p=reject” so forged messages are refused.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
DMARC applies to only part of your email
What it means
What could happen
How an attacker would use it
How to fix it
- Open the TXT record named _dmarc.example.com in your DNS settings.
- Check in your DMARC reports that your legitimate senders pass.If one fails, fix it first.
- Remove “pct=…” from the record, or set it to “pct=100”.When the tag is absent, the rule applies to everything.
- Save and wait a few hours for it to spread.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
You don't receive DMARC reports
What it means
What could happen
How an attacker would use it
How to fix it
- Choose a mailbox just for the reports, such as dmarc@example.com, or use a DMARC reports service.In Ward, your domain's “DMARC reports and reputation” page shows an address you can use when it's available.
- Edit the TXT record named _dmarc.example.com and add “rua=mailto:” followed by that address.Keep the rest of the record as it is, separated with semicolons.
- Save and wait a day or two: providers send their reports once a day.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
DMARC is weaker for subdomains
What it means
What could happen
How an attacker would use it
How to fix it
- Open the TXT record named _dmarc.example.com in your DNS settings.
- Set “sp=” to the same value as “p=” (for example both “reject”), or remove “sp=” so subdomains inherit “p=”.
- Save and wait a few hours for DNS to spread.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
No DKIM signature found
What it means
What could happen
How an attacker would use it
How to fix it
- Open the admin area of your email service and find its DKIM or “email authentication” settings.
- Generate the DKIM key. The service shows one or more DNS records to publish.
- At your DNS host, add those records exactly as shown.
- Go back to the email service and turn signing on once the records have spread.Some services only enable it after a button like “Start” or “Enable”.
- Send a test message to a personal Gmail account to confirm it arrives normally.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
No MTA-STS
What it means
What could happen
How an attacker would use it
How to fix it
- Check which servers receive your email (your MX records) and confirm they support encrypted connections.Big providers such as Google and Microsoft do.
- Create the address mta-sts.example.com in your DNS and a web page behind it with a valid certificate.
- Publish a short policy file at https://mta-sts.example.com/.well-known/mta-sts.txt, in “testing” mode first.The file has lines “version: STSv1”, “mode: testing”, one “mx:” line per mail server and “max_age:”.
- Add a TXT record named _mta-sts.example.com with “v=STSv1; id=” followed by any number you change each time the policy changes.
- Watch the TLS-RPT reports for a few weeks and, if there are no errors, change the mode to “enforce”.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
MTA-STS is broken
What it means
What could happen
How an attacker would use it
How to fix it
- Open https://mta-sts.example.com/.well-known/mta-sts.txt in a browser and note the error you see.A certificate warning, a “not found” page or an empty page each point to a different fix.
- Make sure the name mta-sts.example.com exists in your DNS and points to a web server.
- Install a valid certificate for that name and publish the policy file at the path above.
- Check that the file has “version: STSv1”, a “mode”, one “mx:” line per mail server and a “max_age”.
- If you no longer want MTA-STS, delete the TXT record that announces it instead.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
MTA-STS still in testing mode
What it means
What could happen
How to fix it
- Read your TLS-RPT reports (or ask whoever receives them) for a few weeks.
- If there are no delivery errors, edit the policy file and change “mode: testing” to “mode: enforce”.
- Change the number after “id=” in the _mta-sts TXT record so mail servers notice the new policy.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
No TLS-RPT reports
What it means
What could happen
How to fix it
- Choose a mailbox for the reports, such as tlsrpt@example.com, or a reports service.
- Add a TXT record named _smtp._tls.example.com with the value “v=TLSRPTv1; rua=mailto:” followed by that address.
- Save and give it a day or two: providers send their reports once a day.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Unrecognized sender using your domain
What it means
What could happen
How an attacker would use it
How to fix it
- Open the technical details and note the sender's addresses, its volume and its reverse name (PTR).The reverse name often shows the company behind the server.
- Ask your team if it matches a tool: newsletters, invoicing, CRM, an online store, a website form, a printer or an old server.
- If it's yours, authorize it: add its “include:” to your SPF or turn on DKIM signing with your domain in that service.
- If nobody recognizes it, treat it as impersonation: move your DMARC policy to “quarantine” or “reject” once your own senders pass.
- Warn your customers and team that fake emails may be circulating and not to act on payment changes without calling you.
- Keep reading the reports to confirm the sender disappears.If you suspect a mailbox was compromised, also change its password and turn on two-step verification.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
SPF includes a service that no longer sends
What it means
What could happen
How to fix it
- Check with your team that nobody uses the service behind “include:include”, even occasionally.Yearly campaigns or occasional invoicing tools can go months without sending.
- If it is no longer needed, remove that entry from your SPF record at your DNS host.
- Save, and send a test message to a personal Gmail account to confirm your email still arrives.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.