DomainShield Tower
Customer help center

How to read your domain security report.

Use this guide to understand the score, decide what needs attention, read discovered records, and turn technical findings into a practical remediation plan.

Start here

Read the report in 60 seconds

  1. Check the overall score and posture.Use them as a summary, then read the findings that produced the score.
  2. Review failed controls first.They normally represent missing, invalid, or unavailable protections.
  3. Review warnings next.Warnings may be weak policies, expiring assets, incomplete records, or checks needing confirmation.
  4. Compare with the previous scan.Look for new risks, resolved findings, and unexpected score changes.
  5. Assign and verify remediation.Copy the recommended DNS value carefully, make the change, then scan again after DNS propagation.
Overall posture

What the score means

The score summarizes the controls tested. Failed checks have a greater effect than warnings, while informational items do not necessarily reduce the score.

90-100

Strong

Core controls are healthy. Continue monitoring and review any remaining warnings.

75-89

Good, with improvements

The foundation is useful, but one or more controls should be strengthened.

60-74

Elevated risk

Important gaps exist. Create a remediation plan and address higher-severity findings.

0-59

High risk

Major controls may be missing or failing. Prioritize immediate investigation.

Do not judge the domain by the score alone. A single failed control may matter more to your organization than several passed checks.

Status labels

Passed, warning, failed, and informational

Passed

What it means

The control was found and met the condition tested at scan time.

What to do

Usually no immediate action. Keep monitoring for changes.

Warning

What it means

The control exists but is incomplete, weak, nearing expiry, or could not be fully confirmed.

What to do

Review the evidence and recommended action. Plan a correction.

Failed

What it means

A required control is missing, invalid, unavailable, or presents a material risk.

What to do

Prioritize the finding, assign an owner, and verify the fix.

Informational

What it means

The result provides context or describes a test that was intentionally not performed.

What to do

Read the note. It may still identify an optional improvement.

Finding anatomy

How to read an individual finding

1

Finding name

Identifies the security control, such as DMARC policy or SSL certificate.

2

Result summary

Explains what the scanner observed at the time of the test.

3

Discovered record

Shows the actual public DNS value or evidence returned by the scan. Compare it with the intended configuration.

4

Recommended action

Describes the desired correction. Validate provider-specific values before publishing them.

5

Verification

After making the change, allow for DNS TTL and propagation, then run a new scan to confirm the result.

Warning

DMARC policy

DMARC policy is set to p=none.

Discovered recordv=DMARC1; p=none; rua=mailto:reports@example.comRecommended action

Review legitimate senders and alignment reports, then progress gradually to p=quarantine and p=reject.

Report sections

What each category covers

Email authentication

SPF, DKIM, DMARC, and BIMI help receiving systems distinguish legitimate mail from spoofed messages.

Mail infrastructure

MX, SMTP, reverse DNS, mail TLS, MTA-STS, and TLS-RPT cover routing, reachability, identity, and encryption.

Website and TLS

Website availability, HTTPS redirects, certificates, and browser security headers protect visitors and service continuity.

DNS and registration

DNS propagation, authoritative nameservers, and registration expiry affect every website and email service on the domain.

Reputation

Blocklist checks identify public reputation signals that may affect trust and email delivery.

Change tracking

Understanding scan comparison

  • New: requires action now but did not in the previous scan.
  • Resolved: previously required action and now passes or is informational.
  • Unchanged: remains actionable in both scans.
  • Score delta: shows the numerical change, but always inspect which finding caused it.
Prioritization

What should be fixed first?

  1. Failures affecting active email, web, DNS, or certificate availability.
  2. Spoofing and authentication gaps, especially DMARC, DKIM, and SPF.
  3. Certificate or domain expiration warnings.
  4. Blocklist detections and reputation changes.
  5. Hardening recommendations and informational improvements.
Quick reference

Common terms in the report

SPF
A DNS record listing systems allowed to send mail for a domain.
DKIM
A cryptographic signature added by a mail provider and verified with a DNS public key.
DMARC
A policy that checks SPF/DKIM alignment and tells receivers how to handle failed mail.
BIMI
A standard for displaying an authenticated brand logo at supporting mailbox providers.
MX
DNS records identifying the servers that receive email for a domain.
PTR / reverse DNS
A record mapping an IP address back to a hostname, commonly used as a reputation signal.
MTA-STS
A policy requiring supporting mail servers to use trusted TLS when delivering to your domain.
TLS-RPT
Reports describing failures that prevented encrypted email transport.
SSL/TLS certificate
The digital certificate that identifies a website and enables encrypted HTTPS connections.
Blocklist
A third-party list of domains or IP addresses associated with unwanted or abusive activity.
Important limitations

What a scan cannot prove

Results are based primarily on public DNS, network responses, certificate information, HTTP behavior, registration data, and supported reputation sources.

A passed result does not prove that every user, device, cloud service, mail flow, or internal system is secure. Some controls require provider access or human review.

“Not found” can mean the record is missing, published under a different selector or hostname, not visible to the resolver yet, or temporarily unavailable.

Open-relay testing is intentionally not performed automatically because intrusive probing can be disruptive and misleading.

Need help?

Turn the findings into a remediation plan.

Use the report appendix for technical evidence, then assign owners and verify each correction with a new scan.

Open dashboardContact support