it.com
Excellent, with 1 thing to fix
it.com scored 92/100 (grade A). The main issue is MTA-STS policy file is unreachable.
Checked 2026-10-04 02:19 UTC · fresh check
All checks
MXCan servers find your inbox?Only one MX hostInfo
- Info: Only one MX host
All mail for it.com goes to mx10.it.com. Most hosted providers make that one name highly available; if you run your own server, consider a backup MX.
SPFWho may send as you?No issues foundPass
Nothing to report.
DKIMAre your emails signed?DKIM key publishedPass
- Pass: DKIM key published
it.com publishes a DKIM key under k2, k3, mail.
DMARCWhat happens to fakes?DMARC uses strict alignmentInfo
- Info: DMARC uses strict alignment
With adkim=s or aspf=s the DKIM d= domain or the bounce domain must equal the From domain exactly; a subdomain is not enough. Third-party senders that sign or bounce from a subdomain (or their own domain) will then fail DMARC unless they are configured to use your exact domain.
AlignmentDoes it match your From?No issues foundPass
Nothing to report.
BIMICan inboxes show your logo?No BIMI recordInfo
- Info: No BIMI record
No BIMI record at default._bimi.it.com. BIMI is optional: it shows your logo next to your mail in supporting inboxes once DMARC is enforced.
How to fix this
MTA-STSIs mail to you encrypted?MTA-STS policy file is unreachableNeeds attention
- Warning: MTA-STS policy file is unreachable
https://mta-sts.it.com/.well-known/mta-sts.txt could not be fetched (HTTP 526). Senders cannot apply MTA-STS without the policy file, served over https with a valid certificate.
TLS-RPTWill you hear about failures?TLS-RPT is configuredPass
- Pass: TLS-RPT is configured
TLS reports will be sent to mailto:n08944ft3h@tls.powerdmarc.com.
How to fix it
Prepare BIMIinstruction
BIMI shows your logo next to messages in supporting inboxes, but only for mail that passes DMARC under an enforced policy.
Applies to: default._bimi.it.com
- Enforce DMARC first: p=quarantine or p=reject at 100% (no pct below 100). 2. Convert your logo to an SVG Tiny PS file and host it over HTTPS, for example https://it.com/bimi/logo.svg. 3. For Gmail and Apple Mail, obtain a VMC or CMC certificate for the logo. 4. Publish a TXT record at default._bimi.it.com with v=BIMI1, l= set to the logo URL and a= set to the certificate URL.