1 free scan. No account required.
Create a free Felixous account to save this report and run unlimited scans.
Vol. I · No. 1 — Greater Toronto Area, Canada — Thursday, October 1, 2026 — Managed IT & Cybersecurity
Business Email Security Checker
2026-08-23, 8:27:35 p.m. · Felixous DNS scanner (self-hosted, no third-party APIs)
1 free scan. No account required.
Create a free Felixous account to save this report and run unlimited scans.
No v=DMARC1 TXT record exists at _dmarc.glxreno.com. Receivers have no instructions for handling mail that fails SPF/DKIM, and you get no visibility into spoofing.
Fix: Add a TXT record at _dmarc.glxreno.com: "v=DMARC1; p=quarantine; rua=mailto:[email protected]" as a starting point, then escalate to p=reject once reports confirm legitimate mail passes.
None of the common selectors (google, selector1, selector2, default, mail, k1) answered at *._domainkey.glxreno.com. The domain may still sign mail with a custom selector, so this is not proof DKIM is absent — but no DKIM could be verified.
Fix: Enable DKIM signing in your mail provider and publish the TXT record it generates (e.g. google._domainkey for Google Workspace, selector1/selector2._domainkey for Microsoft 365).
Unauthorized senders are marked but usually still delivered. Softfail is a reasonable transitional state but weaker than -all.
Fix: Once confident every legitimate sender is listed, tighten the record to end in -all.
Google Workspace or Microsoft 365 with SPF, DKIM, and DMARC configured correctly from day one, so your invoices land in inboxes, not spam folders.
Results are informational, not a guarantee of security. These are passive, read-only checks. A clean report does not prove a site is secure, and a finding may have compensating controls we cannot see. Terms