amazontrust.com

amazontrust.com · Last checked 2026-10-04 02:09 UTC

amazontrust.com

Good, with 2 things to fix

amazontrust.com scored 84/100 (grade B). The main issues are DKIM key revoked and external DMARC report address is not authorized.

Checked 2026-10-04 02:09 UTC · fresh check

1 passed2 need attention0 failing5 for information

All checks

MXCan servers find your inbox?Only one MX hostInfo
  • Info: Only one MX host

    All mail for amazontrust.com goes to inbound-smtp.us-east-1.amazonaws.com. Most hosted providers make that one name highly available; if you run your own server, consider a backup MX.

SPFWho may send as you?No issues foundPass

Nothing to report.

DKIMAre your emails signed?DKIM key revokedNeeds attention
  • Warning: DKIM key revoked

    google, selector1, selector2, k1, k2, k3, s1, s2, mail, default, dkim, smtp, mandrill, pm, pm-bounces, mg, mailo, krs, email, sendinblue, brevo, hs1, hs2, amazonses, ses, zendesk1, zendesk2, fd, fd2, protonmail, protonmail2, protonmail3, zoho, everlytickey1, everlytickey2, sig1, cm, mxvault, turbo-smtp, sparkpost, scph0123, kl, kl2, resend, intercom, cf2024-1, cf-bounce publishes an empty p= tag, so any mail still signed with that selector fails DKIM. That is correct after a key rotation; otherwise publish the current key or stop signing with this selector.

DMARCWhat happens to fakes?External DMARC report address is not authorizedNeeds attention
  • Warning: External DMARC report address is not authorized

    Reports go to dmarc.amazon.com, which is outside amazontrust.com. RFC 7489 requires that domain to publish a valid v=DMARC1 TXT record at amazontrust.com._report._dmarc.dmarc.amazon.com; without it receivers will not send you aggregate reports. Your report provider normally publishes this for you.

AlignmentDoes it match your From?SPF alignment is unknownInfo
  • Info: SPF alignment is unknown

    The SPF record of amazontrust.com authorizes no sender (no +ip4, +ip6, +a, +mx, +exists or +ptr term, include of a record that has one, or +all before all), so SPF never passes and cannot align. That is correct for a domain that sends no mail; otherwise DMARC depends on DKIM alone.

BIMICan inboxes show your logo?No BIMI recordInfo
  • Info: No BIMI record

    No BIMI record at default._bimi.amazontrust.com. BIMI is optional: it shows your logo next to your mail in supporting inboxes once DMARC is enforced.

    How to fix this
MTA-STSIs mail to you encrypted?No MTA-STS recordInfo
  • Info: No MTA-STS record

    No MTA-STS record at _mta-sts.amazontrust.com. MTA-STS (RFC 8461) makes sending servers require TLS and a valid certificate when delivering to you, which blocks downgrade attacks.

    How to fix this
TLS-RPTWill you hear about failures?No TLS-RPT recordInfo
  • Info: No TLS-RPT record

    No TLS reporting record at _smtp._tls.amazontrust.com. TLS-RPT (RFC 8460) tells senders where to send daily reports about failed encrypted deliveries to you.

    How to fix this

How to fix it

Publish the MTA-STS recordTXT

Tells sending servers that amazontrust.com publishes an MTA-STS policy at https://mta-sts.amazontrust.com/.well-known/mta-sts.txt. Change the id whenever the policy file changes.

TypeTXT
Name / Host
_mta-sts.amazontrust.com

Some DNS providers want just “_mta-sts” here.

Value
v=STSv1; id=202610040209

Host the MTA-STS policy filepolicy-file

Serve this file over HTTPS with a valid certificate for mta-sts.amazontrust.com. It lists your MX hosts and starts in testing mode; switch to mode: enforce once TLS-RPT reports show no failures.

Location
https://mta-sts.amazontrust.com/.well-known/mta-sts.txt
Contents
version: STSv1
mode: testing
mx: inbound-smtp.us-east-1.amazonaws.com
max_age: 604800

Set up a TLS report addressinstruction

Sending servers will report TLS failures when delivering to amazontrust.com, which you need before enforcing MTA-STS. The address must accept TLS reports; a DMARC report address does not necessarily do so.

Applies to: _smtp._tls.amazontrust.com

  1. Pick an address that will receive TLS reports: a mailbox you read (for example tls-reports@amazontrust.com, created first) or a TLS reporting service. 2. Publish a TXT record at _smtp._tls.amazontrust.com with the value v=TLSRPTv1; rua=mailto:<that address>.

Prepare BIMIinstruction

BIMI shows your logo next to messages in supporting inboxes, but only for mail that passes DMARC under an enforced policy.

Applies to: default._bimi.amazontrust.com

  1. Enforce DMARC first: p=quarantine or p=reject at 100% (no pct below 100). 2. Convert your logo to an SVG Tiny PS file and host it over HTTPS, for example https://amazontrust.com/bimi/logo.svg. 3. For Gmail and Apple Mail, obtain a VMC or CMC certificate for the logo. 4. Publish a TXT record at default._bimi.amazontrust.com with v=BIMI1, l= set to the logo URL and a= set to the certificate URL.