SpoofCheck
🇫🇷Free email security analysis

Results for tecnolaser.eu

63C
This domain is vulnerable to spoofing

SPF

Warning
v=spf1 include:spf.protection.outlook.com include:_spf.tustenasend.it include:musvc.com ip4:151.11.49.218 ~all
Read the guide

DKIM

OK
Selectors: selector1

DMARC

Warning
v=DMARC1; p=none; pct=10; rua=mailto:dmarc@tecnolaser.eu; ruf=mailto:dmarc@tecnolaser.eu
Read the guide

MX

OK
tecnolaser-eu.mail.protection.outlook.com

MTA-STS

Missing

No record found

Read the guide

Recommendations

  1. 1Change your DMARC policy from p=none to p=reject to block spoofing

    With p=none, your DMARC record only monitors — it doesn't actually block spoofed emails. Attackers can still send emails as your domain and they'll be delivered normally. Switching to p=reject instructs receiving servers to drop fraudulent messages before they reach the inbox.

  2. 2Harden your SPF by replacing ~all with -all (hardfail)

    With ~all (softfail), unauthorized senders are flagged but emails are usually still delivered. Switching to -all (hardfail) explicitly tells receiving servers to reject emails from unauthorized sources, providing much stronger protection against spoofing.

  3. 3Add MTA-STS to enforce TLS encryption for incoming emails

    Without MTA-STS, an attacker performing a man-in-the-middle attack can downgrade the connection between mail servers to plaintext, intercepting emails in transit. MTA-STS tells sending servers to only deliver via TLS with a valid certificate, preventing downgrade attacks.

Need help securing your domain?

If you're not sure how to apply these fixes, get in touch and we'll help you out.

Contact us
Check another domain

Badge for your website

Display your email security score on your website.

SpoofCheck badge for tecnolaser.eu
<a href="https://spoofchecker.online/en/email-security/tecnolaser.eu" target="_blank" rel="noopener"><img src="https://spoofchecker.online/api/badge/tecnolaser.eu?score=63&grade=C" alt="Email security score for tecnolaser.eu" height="28"></a>