scopeml.com
Poor, with 2 things to fix
scopeml.com scored 58/100 (grade D). The main issues are no DMARC record and no DKIM key found for the common selectors.
Checked 2026-10-04 18:17 UTC
Publish a DMARC record
Starts DMARC in monitoring mode (p=none), so you can see who sends as scopeml.com before enforcing a policy. Move to quarantine once the reports show only your own services.
_dmarc.scopeml.com
Some DNS providers want just “_dmarc” here.
v=DMARC1; p=none; adkim=r; aspf=r
How to apply it
- Sign in where your domain’s DNS is managed. This is often where you bought the domain, such as Cloudflare, GoDaddy or Namecheap.
- Add a new TXT record with the name and value above.
- Save, then come back and re-check. DNS changes can take up to a few hours to show.
All checks
MXCan servers find your inbox?Domain declares it does not accept mailInfo
- Info: Domain declares it does not accept mail
scopeml.com publishes a null MX (RFC 7505), telling senders it accepts no mail. That is correct for a send-only or parked domain.
SPFWho may send as you?No issues foundPass
Nothing to report.
DKIMAre your emails signed?No DKIM key found for the common selectorsNeeds attention
- Warning: No DKIM key found for the common selectors
None of the 47 selectors probed under scopeml.com publish a DKIM key. DNS cannot list selectors, so a key under a custom selector may exist: find the s= value in the DKIM-Signature header of a message you sent and check that selector. If DKIM is not set up, enable it at each service that sends mail for scopeml.com.
DMARCWhat happens to fakes?No DMARC recordFailing
- Fail: No DMARC record
There is no v=DMARC1 TXT record at _dmarc.scopeml.com. Without DMARC, receivers have no policy for mail that fails SPF and DKIM, and Gmail and Yahoo require one for bulk senders. Start with p=none and a rua address to collect reports.
How to fix this
AlignmentDoes it match your From?SPF alignment is unknownInfo
- Info: SPF alignment is unknown
The SPF record of scopeml.com authorizes no sender (no +ip4, +ip6, +a, +mx, +exists or +ptr term, include of a record that has one, or +all before all), so SPF never passes and cannot align. That is correct for a domain that sends no mail; otherwise DMARC depends on DKIM alone.
BIMICan inboxes show your logo?No BIMI recordInfo
- Info: No BIMI record
No BIMI record at default._bimi.scopeml.com. BIMI is optional: it shows your logo next to your mail in supporting inboxes once DMARC is enforced.
How to fix this
MTA-STSIs mail to you encrypted?No MTA-STS recordInfo
- Info: No MTA-STS record
No MTA-STS record at _mta-sts.scopeml.com. MTA-STS (RFC 8461) makes sending servers require TLS and a valid certificate when delivering to you, which blocks downgrade attacks.
TLS-RPTWill you hear about failures?No TLS-RPT recordInfo
- Info: No TLS-RPT record
No TLS reporting record at _smtp._tls.scopeml.com. TLS-RPT (RFC 8460) tells senders where to send daily reports about failed encrypted deliveries to you.
How to fix this
Other fixes
Choose an external TLS report addressinstruction
A domain that accepts no mail has no inbound TLS to report on, so TLS-RPT is optional here; a reporting address on scopeml.com itself would never receive anything.
Applies to: _smtp._tls.scopeml.com
- scopeml.com publishes a null MX, so it accepts no mail and cannot receive TLS reports itself. If you want TLS-RPT for it, use an address at another domain that receives mail (or a TLS reporting service), then publish a TXT record at _smtp._tls.scopeml.com with the value v=TLSRPTv1; rua=mailto:<that address>.
Prepare BIMIinstruction
BIMI shows your logo next to messages in supporting inboxes, but only for mail that passes DMARC under an enforced policy.
Applies to: default._bimi.scopeml.com
- Enforce DMARC first: p=quarantine or p=reject at 100% (no pct below 100). 2. Convert your logo to an SVG Tiny PS file and host it over HTTPS, for example https://scopeml.com/bimi/logo.svg. 3. For Gmail and Apple Mail, obtain a VMC or CMC certificate for the logo. 4. Publish a TXT record at default._bimi.scopeml.com with v=BIMI1, l= set to the logo URL and a= set to the certificate URL.