id5-sync.com

id5-sync.com · Last checked 2026-10-04 02:15 UTC

id5-sync.com

At risk, with 3 things to fix

id5-sync.com scored 28/100 (grade F). The main issues are no DMARC record and no SPF record, plus 1 more. Detected senders: Google Workspace.

Checked 2026-10-04 02:15 UTC · fresh check

2 passed1 needs attention2 failing3 for informationDetected senders: Google Workspace
Fix this firstThe change with the biggest effect

Publish an SPF record

Lists the sending services detected for id5-sync.com (Google Workspace) and rejects everything else. Add any other service that sends as id5-sync.com before publishing. Changes: Added include:_spf.google.com for Google Workspace.

TypeTXT
Name / Host
id5-sync.com

Some DNS providers want “@” here instead of the full domain.

Value
v=spf1 include:_spf.google.com -all

How to apply it

  1. Sign in where your domain’s DNS is managed. This is often where you bought the domain, such as Cloudflare, GoDaddy or Namecheap.
  2. Add a new TXT record with the name and value above.
  3. Save, then come back and re-check. DNS changes can take up to a few hours to show.

All checks

MXCan servers find your inbox?No issues foundPass

Nothing to report.

SPFWho may send as you?No SPF recordFailing
  • Fail: No SPF record

    id5-sync.com publishes no TXT record starting with "v=spf1", so receivers cannot tell which servers may send mail for it. Publish one SPF record listing every service that sends as id5-sync.com.

    How to fix this
DKIMAre your emails signed?No DKIM key found for the common selectorsNeeds attention
  • Warning: No DKIM key found for the common selectors

    None of the 47 selectors probed under id5-sync.com publish a DKIM key. DNS cannot list selectors, so a key under a custom selector may exist: find the s= value in the DKIM-Signature header of a message you sent and check that selector. If DKIM is not set up, enable it at each service that sends mail for id5-sync.com.

DMARCWhat happens to fakes?No DMARC recordFailing
  • Fail: No DMARC record

    There is no v=DMARC1 TXT record at _dmarc.id5-sync.com. Without DMARC, receivers have no policy for mail that fails SPF and DKIM, and Gmail and Yahoo require one for bulk senders. Start with p=none and a rua address to collect reports.

    How to fix this
AlignmentDoes it match your From?No issues foundPass

Nothing to report.

BIMICan inboxes show your logo?No BIMI recordInfo
  • Info: No BIMI record

    No BIMI record at default._bimi.id5-sync.com. BIMI is optional: it shows your logo next to your mail in supporting inboxes once DMARC is enforced.

    How to fix this
MTA-STSIs mail to you encrypted?No MTA-STS recordInfo
  • Info: No MTA-STS record

    No MTA-STS record at _mta-sts.id5-sync.com. MTA-STS (RFC 8461) makes sending servers require TLS and a valid certificate when delivering to you, which blocks downgrade attacks.

    How to fix this
TLS-RPTWill you hear about failures?No TLS-RPT recordInfo
  • Info: No TLS-RPT record

    No TLS reporting record at _smtp._tls.id5-sync.com. TLS-RPT (RFC 8460) tells senders where to send daily reports about failed encrypted deliveries to you.

    How to fix this

Other fixes

Publish a DMARC recordTXT

Starts DMARC in monitoring mode (p=none), so you can see who sends as id5-sync.com before enforcing a policy. Move to quarantine once the reports show only your own services.

TypeTXT
Name / Host
_dmarc.id5-sync.com

Some DNS providers want just “_dmarc” here.

Value
v=DMARC1; p=none; adkim=r; aspf=r

Enable DKIM for Google Workspaceinstruction

Google Workspace generates the DKIM key for each account, so the exact record must come from Google Workspace. Without DKIM, mail it sends for id5-sync.com cannot pass DMARC through DKIM.

Applies to: google._domainkey.id5-sync.com

  1. In Google Workspace, enable DKIM signing for id5-sync.com: Generate the key in Admin console > Apps > Gmail > Authenticate email, then publish the TXT record shown there. Publish exactly the record Google Workspace shows (TXT or CNAME) at the host name it gives, then turn signing on. Instructions: https://support.google.com/a/answer/174124

Publish the MTA-STS recordTXT

Tells sending servers that id5-sync.com publishes an MTA-STS policy at https://mta-sts.id5-sync.com/.well-known/mta-sts.txt. Change the id whenever the policy file changes.

TypeTXT
Name / Host
_mta-sts.id5-sync.com

Some DNS providers want just “_mta-sts” here.

Value
v=STSv1; id=202610040215

Host the MTA-STS policy filepolicy-file

Serve this file over HTTPS with a valid certificate for mta-sts.id5-sync.com. It lists your MX hosts and starts in testing mode; switch to mode: enforce once TLS-RPT reports show no failures.

Location
https://mta-sts.id5-sync.com/.well-known/mta-sts.txt
Contents
version: STSv1
mode: testing
mx: aspmx.l.google.com
mx: alt1.aspmx.l.google.com
mx: alt2.aspmx.l.google.com
mx: aspmx2.googlemail.com
mx: aspmx3.googlemail.com
max_age: 604800

Set up a TLS report addressinstruction

Sending servers will report TLS failures when delivering to id5-sync.com, which you need before enforcing MTA-STS. The address must accept TLS reports; a DMARC report address does not necessarily do so.

Applies to: _smtp._tls.id5-sync.com

  1. Pick an address that will receive TLS reports: a mailbox you read (for example tls-reports@id5-sync.com, created first) or a TLS reporting service. 2. Publish a TXT record at _smtp._tls.id5-sync.com with the value v=TLSRPTv1; rua=mailto:<that address>.

Prepare BIMIinstruction

BIMI shows your logo next to messages in supporting inboxes, but only for mail that passes DMARC under an enforced policy.

Applies to: default._bimi.id5-sync.com

  1. Enforce DMARC first: p=quarantine or p=reject at 100% (no pct below 100). 2. Convert your logo to an SVG Tiny PS file and host it over HTTPS, for example https://id5-sync.com/bimi/logo.svg. 3. For Gmail and Apple Mail, obtain a VMC or CMC certificate for the logo. 4. Publish a TXT record at default._bimi.id5-sync.com with v=BIMI1, l= set to the logo URL and a= set to the certificate URL.