How to read results
Each check returns one of four statuses:
- pass — Expected DNS record shape is present (for SPF/DKIM/DMARC core checks).
- warn — Something is present but incomplete, soft, or monitoring-only (for example
p=noneor~all). - fail — Important SPF or DMARC DNS data is missing or clearly broken (for example multiple SPF records).
- unknown — Optional signals (BIMI / MTA-STS) absent, or results inconclusive.
BIMI and MTA-STS
AuthDNS only checks DNS presence for BIMI (default._bimi) and MTA-STS (_mta-sts). It does not fetch BIMI logos or MTA-STS policy files over HTTPS.
Overall status
Overall status is driven by SPF, DKIM, and DMARC — not by optional BIMI/MTA-STS.
Sharing
Reports use opaque high-entropy IDs. There is no public list of reports; only direct links work.