bbc.co.uk

bbc.co.uk · Last checked 2026-10-04 02:06 UTC

bbc.co.uk

Good, with 2 things to fix

bbc.co.uk scored 80/100 (grade B). The main issues are no DKIM key found for the common selectors and DMARC alignment: DKIM alignment is unlikely under adkim=s.

Checked 2026-10-04 02:06 UTC · fresh check

2 passed2 need attention0 failing4 for information

All checks

MXCan servers find your inbox?No issues foundPass

Nothing to report.

SPFWho may send as you?SPF ends in softfail (~all)Info
  • Info: SPF ends in softfail (~all)

    "~all" is common and works well with DMARC. "-all" is stricter; switch when you are sure every sender is listed.

DKIMAre your emails signed?No DKIM key found for the common selectorsNeeds attention
  • Warning: No DKIM key found for the common selectors

    None of the 47 selectors probed under bbc.co.uk publish a DKIM key. DNS cannot list selectors, so a key under a custom selector may exist: find the s= value in the DKIM-Signature header of a message you sent and check that selector. If DKIM is not set up, enable it at each service that sends mail for bbc.co.uk.

DMARCWhat happens to fakes?DMARC uses strict alignmentInfo
  • Info: DMARC uses strict alignment

    With adkim=s or aspf=s the DKIM d= domain or the bounce domain must equal the From domain exactly; a subdomain is not enough. Third-party senders that sign or bounce from a subdomain (or their own domain) will then fail DMARC unless they are configured to use your exact domain.

AlignmentDoes it match your From?DKIM alignment is unlikely under adkim=sNeeds attention
  • Warning: DKIM alignment is unlikely under adkim=s

    This is a heuristic. No DKIM key was found at bbc.co.uk under the selectors we probed, and adkim=s requires the signing d= domain to equal bbc.co.uk exactly. If your mail is signed with a provider's domain or a subdomain, DKIM will not align. A key may exist under a selector we did not try; send a test message to confirm.

BIMICan inboxes show your logo?No issues foundPass

Nothing to report.

MTA-STSIs mail to you encrypted?No MTA-STS recordInfo
  • Info: No MTA-STS record

    No MTA-STS record at _mta-sts.bbc.co.uk. MTA-STS (RFC 8461) makes sending servers require TLS and a valid certificate when delivering to you, which blocks downgrade attacks.

    How to fix this
TLS-RPTWill you hear about failures?No TLS-RPT recordInfo
  • Info: No TLS-RPT record

    No TLS reporting record at _smtp._tls.bbc.co.uk. TLS-RPT (RFC 8460) tells senders where to send daily reports about failed encrypted deliveries to you.

    How to fix this

How to fix it

Publish the MTA-STS recordTXT

Tells sending servers that bbc.co.uk publishes an MTA-STS policy at https://mta-sts.bbc.co.uk/.well-known/mta-sts.txt. Change the id whenever the policy file changes.

TypeTXT
Name / Host
_mta-sts.bbc.co.uk

Some DNS providers want just “_mta-sts” here.

Value
v=STSv1; id=202610040206

Host the MTA-STS policy filepolicy-file

Serve this file over HTTPS with a valid certificate for mta-sts.bbc.co.uk. It lists your MX hosts and starts in testing mode; switch to mode: enforce once TLS-RPT reports show no failures.

Location
https://mta-sts.bbc.co.uk/.well-known/mta-sts.txt
Contents
version: STSv1
mode: testing
mx: cluster1.eu.messagelabs.com
mx: cluster1a.eu.messagelabs.com
max_age: 604800

Set up a TLS report addressinstruction

Sending servers will report TLS failures when delivering to bbc.co.uk, which you need before enforcing MTA-STS. The address must accept TLS reports; a DMARC report address does not necessarily do so.

Applies to: _smtp._tls.bbc.co.uk

  1. Pick an address that will receive TLS reports: a mailbox you read (for example tls-reports@bbc.co.uk, created first) or a TLS reporting service. 2. Publish a TXT record at _smtp._tls.bbc.co.uk with the value v=TLSRPTv1; rua=mailto:<that address>.