Missing SPF, DKIM, or DMARC Records

Low Severity Technical Guide

Vulnerability Description

Without proper email authentication records, malicious actors can forge emails from your domain name, damaging your brand reputation and triggering phishing alerts.

Remediation Guide

To resolve this vulnerability, follow these config changes or developer practices:

Create and publish SPF, DKIM, and DMARC TXT records in your DNS zones to specify authorized mail servers and instruct recipient mailboxes how to handle forged mail.

Verify Your Fix

After applying the remediation, run an external attack-surface scan to verify that the vulnerability is no longer detected by WebScanify.

Is your website vulnerable?

Run a free security scan now to identify missing headers, outdated JS, and other deployment vulnerabilities.