worldbank.org

worldbank.org · Last checked 2026-10-04 02:19 UTC

worldbank.org

Excellent, with 1 thing to fix

worldbank.org scored 92/100 (grade A). The main issue is DKIM key shorter than 2048 bits.

Checked 2026-10-04 02:19 UTC · fresh check

4 passed1 needs attention0 failing3 for information

All checks

MXCan servers find your inbox?No issues foundPass

Nothing to report.

SPFWho may send as you?SPF ends in softfail (~all)Info
  • Info: SPF ends in softfail (~all)

    "~all" is common and works well with DMARC. "-all" is stricter; switch when you are sure every sender is listed.

DKIMAre your emails signed?DKIM key shorter than 2048 bitsNeeds attention
  • Warning: DKIM key shorter than 2048 bits

    k1 (1024-bit), s2 (1024-bit) uses an RSA key below 2048 bits. Short keys can be factored and some receivers treat them as weak. Rotate to a 2048-bit key at your sending provider.

  • Pass: DKIM key published

    worldbank.org publishes a DKIM key under k1, k2, k3, s1, s2.

DMARCWhat happens to fakes?No issues foundPass

Nothing to report.

AlignmentDoes it match your From?SPF alignment is unknownInfo
  • Info: SPF alignment is unknown

    The SPF record of worldbank.org authorizes no sender (no +ip4, +ip6, +a, +mx, +exists or +ptr term, include of a record that has one, or +all before all), so SPF never passes and cannot align. That is correct for a domain that sends no mail; otherwise DMARC depends on DKIM alone.

BIMICan inboxes show your logo?No issues foundPass

Nothing to report.

MTA-STSIs mail to you encrypted?MTA-STS is in testing modeInfo
  • Info: MTA-STS is in testing mode

    Senders report TLS failures (with TLS-RPT) but still deliver. Switch to mode: enforce once the reports are clean.

TLS-RPTWill you hear about failures?TLS-RPT is configuredPass
  • Pass: TLS-RPT is configured

    TLS reports will be sent to mailto:tls-report@vali.email.