arrow_backBack to your run
Low carddns.spf_missing

Your domain doesn’t name its real senders

Play this card on https://example.com. Everything a developer (or your AI agent) needs to fix and verify it — free. Fixing your own site is never paywalled.

visibilityCard text — what this means

Demo DNS evidence shows no SPF TXT record for the domain.

SPF identifies which mail servers are allowed to send mail for the domain.

Preview ingestion only uses sanitized DNS TXT evidence and does not validate every third-party sender.

playing_cardsHow to play it

Publish an SPF TXT record that covers approved mail providers without making the policy overly broad.

  1. 1Inventory legitimate mail senders for the domain.
  2. 2Publish a v=spf1 TXT record with approved include or IP mechanisms.
  3. 3Collect fresh DNS evidence showing SPF is visible after propagation.

Fix it on your stack

Add this record at your DNS provider — it's the same regardless of web stack.

dns
Type: TXT
Host/Name: @
Value: v=spf1 include:_spf.your-mail-provider.example -all

infoList only the providers that send mail for your domain. Replace the include with your provider's SPF host. Add this record at your DNS provider (registrar or DNS host) — it is the same regardless of web stack.

workspace_premiumClaim your endorsement

Sanitized DNS evidence showing a v=spf1 TXT record for the public target.

Evidence needed: Sanitized DNS evidence showing a v=spf1 TXT record for the public target.

Related controls

Readiness mapping only — evidence relevant to these controls. Pazmo does not determine, certify, or guarantee compliance.

  • A.8.21 · Security of network services (ISO/IEC 27001:2022)
Email securityVendor readiness