Domain status and security grade explained

ShieldMarc describes each domain in two ways. Inside your account, every domain has one status, a few words that tell you whether it needs you. The security grade, a letter from A+ to F, is an outside reading of how well the domain is protected.

Your domain's status

The status appears beside each domain on the Domains page and at the top of the domain's own page, with a short reason and, when there is one, the next step.

  • Setting up: we are waiting for, or checking, your DMARC record with your ShieldMarc reporting address. The next step is Show the record.
  • Monitoring only: your policy is p=none, so receivers deliver fakes as normal. Check if you're ready shows whether you can safely tighten it.
  • Fakes to spam: your policy is p=quarantine, so receivers send fakes to spam.
  • Blocking on: your policy is p=reject, so receivers refuse fakes.
  • Needs you: something needs action now. This is the only red status.

A domain Needs you when a check you have turned on finds that its SSL certificate has expired, is invalid or ends within 7 days, its website is down, its registration has expired or ends within 14 days, or a dangerous lookalike domain has been registered. It also needs you when we find a critical problem, or when reports that were arriving stop for over a week. The SSL, uptime, registration and lookalike checks start switched off: turn them on from the domain's page under Checks.

When reports are more than two days late, the reason changes to "No reports for N days", so you can check the record before it becomes urgent.

Your Home page

Home lists everything that needs you across all your domains, in two groups. Now is for things to deal with today. Coming up is for things to plan for, such as a certificate or registration renewal in the next month or two. Each item has one button that takes you to the fix, and when nothing needs you, Home says so.

The security grade

The free Domain Trust Check and the scan report we email give a domain a letter from A+ to F, and the same grade appears on each domain's page under Technical details. It is an outside reading: it looks only at public DNS, certificate and registration details, the same things an attacker can see.

The checks are weighted so that no single layer can carry the grade. A domain that gets email authentication right, with DMARC at reject on the domain and its subdomains and a valid certificate, earns a B on its own. The A grades also need most of the transport and DNS layer.

The checks behind the grade

  • The basics: an SPF record, a DMARC record, DMARC aggregate reporting (rua=) and a valid SSL certificate.
  • Enforcement: a DMARC policy of p=quarantine or stricter, and an SPF record that ends in ~all or -all.
  • Full enforcement: p=reject; a subdomain policy of reject, set with sp=reject or inherited from p=reject; a policy that covers all of your mail (no pct= below 100); and an SPF record within the 10 DNS lookup limit.
  • Transport and DNS hardening: MTA-STS, TLS-RPT, DNSSEC, certificate issuance protection (CAA) and a registrar transfer lock.

Domain registration expiry is shown for information only. We tell you how many days are left, but it never lowers the grade. DKIM is not graded by the public check, because nothing in DNS lists which selectors a domain signs with; use the DKIM Checker to test a selector.

Duplicate records count as missing

Two DMARC records mean receivers apply no policy at all, so we treat the domain as having no DMARC. Two SPF records are a permanent error, so SPF stops protecting you whatever the qualifier says. In both cases, merge them into one record.

Every domain is held to the same standard

There is no leniency for parked or non-sending domains. A domain with no MX records is checked against the same baseline as your main sending domain, because an unused domain with no DMARC is exactly what an attacker wants.

What to fix first

The free check lists the fixes that matter most, basics first, because hardening protects little while anyone can still send mail as you. In the free check, changes that can affect live mail are flagged: moving DMARC to quarantine or reject is marked High risk change, and tightening SPF or the subdomain policy is marked Review before applying.