mcafee.com
Good, with 2 things to fix
mcafee.com scored 84/100 (grade B). The main issues are BIMI logo is unreachable and DKIM key shorter than 2048 bits. Detected senders: Microsoft 365.
Checked 2026-10-04 02:11 UTC · fresh check
All checks
MXCan servers find your inbox?Only one MX hostInfo
- Info: Only one MX host
All mail for mcafee.com goes to mcafee-com.mail.protection.outlook.com. Most hosted providers make that one name highly available; if you run your own server, consider a backup MX.
SPFWho may send as you?No issues foundPass
Nothing to report.
DKIMAre your emails signed?DKIM key shorter than 2048 bitsNeeds attention
- Warning: DKIM key shorter than 2048 bits
selector1 (1024-bit) uses an RSA key below 2048 bits. Short keys can be factored and some receivers treat them as weak. Rotate to a 2048-bit key at your sending provider.
- Pass: DKIM key published
mcafee.com publishes a DKIM key under selector1.
DMARCWhat happens to fakes?No issues foundPass
Nothing to report.
AlignmentDoes it match your From?SPF alignment is unknownInfo
- Info: SPF alignment is unknown
The SPF record of mcafee.com authorizes no sender (no +ip4, +ip6, +a, +mx, +exists or +ptr term, include of a record that has one, or +all before all), so SPF never passes and cannot align. That is correct for a domain that sends no mail; otherwise DMARC depends on DKIM alone.
BIMICan inboxes show your logo?BIMI logo is unreachableNeeds attention
- Warning: BIMI logo is unreachable
The SVG at https://www.mcafee.com/bimigroup/mcafee_llc_1348033943.svg could not be fetched (HTTP 520). Mailbox providers will not show the logo.
MTA-STSIs mail to you encrypted?No MTA-STS recordInfo
- Info: No MTA-STS record
No MTA-STS record at _mta-sts.mcafee.com. MTA-STS (RFC 8461) makes sending servers require TLS and a valid certificate when delivering to you, which blocks downgrade attacks.
How to fix this
TLS-RPTWill you hear about failures?No TLS-RPT recordInfo
- Info: No TLS-RPT record
No TLS reporting record at _smtp._tls.mcafee.com. TLS-RPT (RFC 8460) tells senders where to send daily reports about failed encrypted deliveries to you.
How to fix this
How to fix it
Publish the MTA-STS recordTXT
Tells sending servers that mcafee.com publishes an MTA-STS policy at https://mta-sts.mcafee.com/.well-known/mta-sts.txt. Change the id whenever the policy file changes.
_mta-sts.mcafee.com
Some DNS providers want just “_mta-sts” here.
v=STSv1; id=202610040211
Host the MTA-STS policy filepolicy-file
Serve this file over HTTPS with a valid certificate for mta-sts.mcafee.com. It lists your MX hosts and starts in testing mode; switch to mode: enforce once TLS-RPT reports show no failures.
https://mta-sts.mcafee.com/.well-known/mta-sts.txt
version: STSv1 mode: testing mx: mcafee-com.mail.protection.outlook.com max_age: 604800
Set up a TLS report addressinstruction
Sending servers will report TLS failures when delivering to mcafee.com, which you need before enforcing MTA-STS. The address must accept TLS reports; a DMARC report address does not necessarily do so.
Applies to: _smtp._tls.mcafee.com
- Pick an address that will receive TLS reports: a mailbox you read (for example tls-reports@mcafee.com, created first) or a TLS reporting service. 2. Publish a TXT record at _smtp._tls.mcafee.com with the value v=TLSRPTv1; rua=mailto:<that address>.