firefox.com
Excellent: no problems found
firefox.com scored 100/100 (grade A). No problems were found in the checks that ran. Detected senders: Google Workspace, Amazon SES and Zendesk.
Checked 2026-10-04 02:12 UTC · fresh check
All checks
MXCan servers find your inbox?Only one MX hostInfo
- Info: Only one MX host
All mail for firefox.com goes to smtp.google.com. Most hosted providers make that one name highly available; if you run your own server, consider a backup MX.
SPFWho may send as you?No issues foundPass
Nothing to report.
DKIMAre your emails signed?DKIM key publishedPass
- Pass: DKIM key published
firefox.com publishes a DKIM key under zendesk1, zendesk2.
DMARCWhat happens to fakes?No issues foundPass
Nothing to report.
AlignmentDoes it match your From?SPF alignment depends on a custom Return-PathInfo
- Info: SPF alignment depends on a custom Return-Path
This is a heuristic. Your SPF record only authorizes third-party senders (amazonses.com, mail.zendesk.com). By default they bounce from their own Return-Path domain, and SPF then passes for that domain, not firefox.com. Even relaxed alignment needs the Return-Path's organizational domain to be firefox.com, so set up a custom Return-Path (bounce) domain under firefox.com with each provider, and sign with DKIM as firefox.com.
BIMICan inboxes show your logo?No BIMI recordInfo
- Info: No BIMI record
No BIMI record at default._bimi.firefox.com. BIMI is optional: it shows your logo next to your mail in supporting inboxes once DMARC is enforced.
How to fix this
MTA-STSIs mail to you encrypted?No MTA-STS recordInfo
- Info: No MTA-STS record
No MTA-STS record at _mta-sts.firefox.com. MTA-STS (RFC 8461) makes sending servers require TLS and a valid certificate when delivering to you, which blocks downgrade attacks.
How to fix this
TLS-RPTWill you hear about failures?No TLS-RPT recordInfo
- Info: No TLS-RPT record
No TLS reporting record at _smtp._tls.firefox.com. TLS-RPT (RFC 8460) tells senders where to send daily reports about failed encrypted deliveries to you.
How to fix this
How to fix it
Publish the MTA-STS recordTXT
Tells sending servers that firefox.com publishes an MTA-STS policy at https://mta-sts.firefox.com/.well-known/mta-sts.txt. Change the id whenever the policy file changes.
_mta-sts.firefox.com
Some DNS providers want just “_mta-sts” here.
v=STSv1; id=202610040212
Host the MTA-STS policy filepolicy-file
Serve this file over HTTPS with a valid certificate for mta-sts.firefox.com. It lists your MX hosts and starts in testing mode; switch to mode: enforce once TLS-RPT reports show no failures.
https://mta-sts.firefox.com/.well-known/mta-sts.txt
version: STSv1 mode: testing mx: smtp.google.com max_age: 604800
Set up a TLS report addressinstruction
Sending servers will report TLS failures when delivering to firefox.com, which you need before enforcing MTA-STS. The address must accept TLS reports; a DMARC report address does not necessarily do so.
Applies to: _smtp._tls.firefox.com
- Pick an address that will receive TLS reports: a mailbox you read (for example tls-reports@firefox.com, created first) or a TLS reporting service. 2. Publish a TXT record at _smtp._tls.firefox.com with the value v=TLSRPTv1; rua=mailto:<that address>.
Prepare BIMIinstruction
BIMI shows your logo next to messages in supporting inboxes, but only for mail that passes DMARC under an enforced policy.
Applies to: default._bimi.firefox.com
- Enforce DMARC first: p=quarantine or p=reject at 100% (no pct below 100). 2. Convert your logo to an SVG Tiny PS file and host it over HTTPS, for example https://firefox.com/bimi/logo.svg. 3. For Gmail and Apple Mail, obtain a VMC or CMC certificate for the logo. 4. Publish a TXT record at default._bimi.firefox.com with v=BIMI1, l= set to the logo URL and a= set to the certificate URL.