Talk to us
Skip to main content

Safinity Axon · Email health scanner

Is your email actually getting through?

Type your domain. In about a minute, Axon checks the public records that email providers use to decide whether to trust your mail — then tells you, in plain language, what's wrong and what to fix first.

  • No account or email needed
  • Reads public DNS records only
  • Never sends email to your server

What we check

Email authentication

The records that prove mail claiming to be from you really is.

Mail routing

The signposts that tell the world where to deliver your mail.

Mail server connection

Whether your mail server answers and can encrypt the connection.

Reputation & blocklists

Whether your mail servers appear on public blocklists.

Policy & reporting

The policies that request encryption and collect problem reports.

See what a report looks like

Sample

A real Axon report, rendered from our published test fixture.

Score 72 out of 100, grade C — Needs improvement
Failing

No DMARC policy is published

DMARC record · Checked 1 day ago

What we found

We checked for a DMARC record at _dmarc.example.com and found none.

Why it matters

Without DMARC, attackers can send email that appears to come from your domain, and you will not receive reports when that happens.

What to do

Add a DMARC record starting with p=none to monitor delivery, then move to p=quarantine or p=reject as you gain confidence.

Expected improvement

Up to +12 points — potentially

Technical details

Check: auth_dmarc.record

Category: Email authentication (authentication)

Checked: 2026-09-11 08:30 UTC

records: []

Warning

SPF record ends in a soft fail (~all)

SPF policy · Checked 1 day ago

What we found

Your SPF record ends with ~all, which tells receiving servers to be suspicious but still accept the message.

Why it matters

A soft fail is treated inconsistently by different providers, so forged mail from your domain may still be delivered.

What to do

Change the final mechanism to -all once you are confident no legitimate senders are missing from the record.

Expected improvement

Up to +6 points — potentially

Technical details

Check: auth_spf.evaluation

Category: Email authentication (authentication)

Checked: 2026-09-11 08:30 UTC

record: v=spf1 include:_spf.example.com ~all

Warning

DKIM key is only 1024 bits

DKIM key · Checked 1 day ago

What we found

The DKIM key at google._domainkey.example.com is a 1024-bit RSA key.

Why it matters

1024-bit RSA keys are weaker and some providers now expect 2048 bits, which can affect deliverability.

What to do

Rotate your DKIM key to 2048 bits and update the record, keeping both keys valid during the transition.

Expected improvement

Up to +4 points — potentially

Technical details

Check: auth_dkim.selector

Category: Email authentication (authentication)

Checked: 2026-09-11 08:30 UTC

keySize: 1024

Questions about your email setup?