Skip to content
láb.comLab Notes

Report sheet LN-10 · filed 27 Sept 2026

Email security doctor: a mail check that writes the fix

Nine kinds of record read and graded by a printed rubric — then the exact records to publish, checked against their RFCs.

Instrument
labs.llc/domains/email/
Shelf on labs.llc
Studio & Tools · Internet
Bench
Local copy of the build-537 files
Run
27 Sept 2026 · 20:12–20:13 UTC
Controls
Internet.nl email test · MxToolbox
Evidence
Source lines in the build; timed reads

Aim

The Email security doctor is one of the ten instruments on labs.llc’s /domains/ desk. Type a domain and it reads the records that decide whether mail to and from it can be trusted — nine kinds, from MX and SPF to MTA-STS and CAA — grades them by a rubric printed in full on the page, explains each miss, and writes the DNS records to publish.

It is for owners and administrators of small and medium domains. We ran it on one real domain from end to end.

Method

Apparatus: what it reads, and where the work happens

The work is split. The page (domains/assets/js/dc-email.js) calls a same-origin relay, tools.php?op=email (line 1169). On the server, tools_email.php reads MX with provider detection, the whole SPF tree against RFC 7208’s ten-lookup and two-void-lookup limits, every DMARC tag, DKIM under 44 selectors with key type and size, and MTA-STS — the TXT record plus the policy fetched over HTTPS with a pinned address, a 64 KB cap, a 6-second timeout and no redirects — then TLS-RPT, BIMI, DNSSEC and CAA (1–39). DNS goes to Google Public DNS, with Cloudflare as fallback.

In the browser, dc-email.js holds a grammar for each record, diagnoses against the printed rubric (442–466) and writes validated fixes with the grade they would reach. It refuses to invent a DKIM key, to call an unreadable record missing, to point BIMI at a logo that does not exist, or to add a report address to a domain that takes no mail (21–25).

It reads

  • Google Public DNS, Cloudflare 1.1.1.1 as fallback, queried by the same-origin relay
  • The domain’s own MTA-STS policy file, fetched by the relay
  • The Public Suffix List and IANA data, for normalising the domain

Procedure

On 27 September 2026 (20:12 UTC) we fetched the page, called the relay for github.com exactly as the page does, then ran the page’s own diagnosis in JavaScriptCore on the relay’s answer and compared the two grades.

Result

Fig. 11280 × 800

The email page of the labs.llc domains desk, headed DomainChaos: the headline ‘Who may send as you. And the records that say so.’, a domain input with an Examine button, and suggested domains to try.
Fig. 1. The opening screen of labs.llc/domains/email/ at desktop width, captured from the local copy of build 537.

Fig. 2390 × 844

The email page at phone width: the headline and introduction in one column, then the domain input beside its Examine button, with suggested domains below.
Fig. 2. The same page at phone width.

Table 1 · Run log, 27 September 2026

No.ReadingUTCWhat came back
1PageHTTP 200, 78,495 bytes
2Relay, github.comHTTP 200, 13,682 bytes in 0.09 s; 65 DNS questions; MX on Microsoft 365; SPF ~all at 10 of 10 lookups; DMARC p=quarantine, sp=reject; 9 of 44 DKIM selectors found, four keys 1024-bit; no MTA-STS, TLS-RPT or BIMI; unsigned; 7 CAA records; STARTTLS not tested
3The page’s diagnosisB, 73 of 100 — SPF 25/25, DMARC 28/30, DKIM 20/20, MTA-STS 0/10, TLS-RPT 0/5, BIMI 0/5, DNSSEC 0/5; projected A, 86, after the fixes it wrote
4The relay’s own gradeC, 60, with different weights (DKIM out of 15, DNSSEC out of 10) and a BIMI logo address the page declines to use

The prescription was concrete: a TLS-RPT record, an MTA-STS TXT record, and a policy file in testing mode naming github.com’s actual MX. But the same data carried two grades, and a reader of the JSON would see a different number from a reader of the page.

Discussion

Two controls: the same job done elsewhere on the web. Each was read on its own page on the date shown, and each is better than Email security doctor at something.

Internet.nl — email test

Checked .

A test from the Internet community and the Dutch government that checks a mail domain for IPv6, DNSSEC, DMARC, DKIM and SPF, STARTTLS and DANE, and RPKI, with an overall percentage and results per section and subtest.

Where it is better

  • Tests transport security on the mail servers — STARTTLS and DANE — which the labs tool cannot.
  • Covers IPv6 and RPKI.
  • A public-interest initiative with government involvement.

Where Email security doctor goes further

  • Checks MTA-STS (fetching and matching the policy file), TLS-RPT and BIMI, none of which the internet.nl page listed.
  • Writes the records to publish, grammar-checked, with the grade they would reach.

MxToolbox Email Health Report

Checked .

A domain email-health report that checks more than 100 domain and IP blacklists, tests each MX server and runs over 15 DNS tests; a paid monitor runs over 30 tests every few minutes and alerts; free users get one check every 24 hours.

Where it is better

  • Blacklist coverage and live mail-server checks.
  • Continuous monitoring with alerts, for subscribers.

Where Email security doctor goes further

  • No account and no daily limit stated on the page; the rubric is printed point by point.
  • Counts SPF lookups and void lookups through the whole tree and probes 44 DKIM selectors, saying plainly when a wildcard makes DKIM unknowable.

Sources of error: where it falls short

  1. No STARTTLS, DANE or IPv6 reachability tests — port 25 is blocked on the host, and the tool says so.
  2. No blacklist checks, monitoring or alerts.
  3. DKIM discovery guesses 44 selectors: an unusual one will be missed, and a wildcard zone makes the answer unknowable (both stated).
  4. Two graders that disagree: C, 60 in the relay’s JSON; B, 73 on the page.
  5. The DKIM score takes the best key, so github.com scored 20 of 20 though four of nine keys are 1024-bit — worth 14 on the rubric.

Conclusion

Findinggithub.com graded B, 73, with a path to A; the relay’s own JSON said C, 60.

The doctor goes past pass and fail: it follows SPF to the last include, counts the limits where records quietly break, fetches MTA-STS under tight rules, prints its rubric, and hands over records it has checked against their standards, refusing to invent the ones it cannot know. On github.com it found a B with a clear route to an A. It should retire the second grade in its JSON and score DKIM by the weakest key. For STARTTLS and DANE, use internet.nl; for blacklists and monitoring, MxToolbox.

Try Email security doctor on labs.llc All ten sheets