Report sheet LN-10 · filed 27 Sept 2026
Email security doctor: a mail check that writes the fix
Nine kinds of record read and graded by a printed rubric — then the exact records to publish, checked against their RFCs.
- Instrument
- labs.llc/domains/email/
- Shelf on labs.llc
- Studio & Tools · Internet
- Bench
- Local copy of the build-537 files
- Run
- 27 Sept 2026 · 20:12–20:13 UTC
- Controls
- Internet.nl email test · MxToolbox
- Evidence
- Source lines in the build; timed reads
Aim
The Email security doctor is one of the ten instruments on labs.llc’s /domains/ desk. Type a domain and it reads the records that decide whether mail to and from it can be trusted — nine kinds, from MX and SPF to MTA-STS and CAA — grades them by a rubric printed in full on the page, explains each miss, and writes the DNS records to publish.
It is for owners and administrators of small and medium domains. We ran it on one real domain from end to end.
Method
Apparatus: what it reads, and where the work happens
The work is split. The page (domains/assets/js/dc-email.js) calls a same-origin relay, tools.php?op=email (line 1169). On the server, tools_email.php reads MX with provider detection, the whole SPF tree against RFC 7208’s ten-lookup and two-void-lookup limits, every DMARC tag, DKIM under 44 selectors with key type and size, and MTA-STS — the TXT record plus the policy fetched over HTTPS with a pinned address, a 64 KB cap, a 6-second timeout and no redirects — then TLS-RPT, BIMI, DNSSEC and CAA (1–39). DNS goes to Google Public DNS, with Cloudflare as fallback.
In the browser, dc-email.js holds a grammar for each record, diagnoses against the printed rubric (442–466) and writes validated fixes with the grade they would reach. It refuses to invent a DKIM key, to call an unreadable record missing, to point BIMI at a logo that does not exist, or to add a report address to a domain that takes no mail (21–25).
It reads
- Google Public DNS, Cloudflare 1.1.1.1 as fallback, queried by the same-origin relay
- The domain’s own MTA-STS policy file, fetched by the relay
- The Public Suffix List and IANA data, for normalising the domain
Procedure
On 27 September 2026 (20:12 UTC) we fetched the page, called the relay for github.com exactly as the page does, then ran the page’s own diagnosis in JavaScriptCore on the relay’s answer and compared the two grades.
Result
Fig. 11280 × 800
Fig. 2390 × 844
Table 1 · Run log, 27 September 2026
| No. | Reading | UTC | What came back |
|---|---|---|---|
| 1 | Page | HTTP 200, 78,495 bytes | |
| 2 | Relay, github.com | HTTP 200, 13,682 bytes in 0.09 s; 65 DNS questions; MX on Microsoft 365; SPF ~all at 10 of 10 lookups; DMARC p=quarantine, sp=reject; 9 of 44 DKIM selectors found, four keys 1024-bit; no MTA-STS, TLS-RPT or BIMI; unsigned; 7 CAA records; STARTTLS not tested | |
| 3 | The page’s diagnosis | B, 73 of 100 — SPF 25/25, DMARC 28/30, DKIM 20/20, MTA-STS 0/10, TLS-RPT 0/5, BIMI 0/5, DNSSEC 0/5; projected A, 86, after the fixes it wrote | |
| 4 | The relay’s own grade | C, 60, with different weights (DKIM out of 15, DNSSEC out of 10) and a BIMI logo address the page declines to use |
The prescription was concrete: a TLS-RPT record, an MTA-STS TXT record, and a policy file in testing mode naming github.com’s actual MX. But the same data carried two grades, and a reader of the JSON would see a different number from a reader of the page.
Discussion
Two controls: the same job done elsewhere on the web. Each was read on its own page on the date shown, and each is better than Email security doctor at something.
Internet.nl — email test
Checked .
A test from the Internet community and the Dutch government that checks a mail domain for IPv6, DNSSEC, DMARC, DKIM and SPF, STARTTLS and DANE, and RPKI, with an overall percentage and results per section and subtest.
Where it is better
- Tests transport security on the mail servers — STARTTLS and DANE — which the labs tool cannot.
- Covers IPv6 and RPKI.
- A public-interest initiative with government involvement.
Where Email security doctor goes further
- Checks MTA-STS (fetching and matching the policy file), TLS-RPT and BIMI, none of which the internet.nl page listed.
- Writes the records to publish, grammar-checked, with the grade they would reach.
MxToolbox Email Health Report
Checked .
A domain email-health report that checks more than 100 domain and IP blacklists, tests each MX server and runs over 15 DNS tests; a paid monitor runs over 30 tests every few minutes and alerts; free users get one check every 24 hours.
Where it is better
- Blacklist coverage and live mail-server checks.
- Continuous monitoring with alerts, for subscribers.
Where Email security doctor goes further
- No account and no daily limit stated on the page; the rubric is printed point by point.
- Counts SPF lookups and void lookups through the whole tree and probes 44 DKIM selectors, saying plainly when a wildcard makes DKIM unknowable.
Sources of error: where it falls short
- No STARTTLS, DANE or IPv6 reachability tests — port 25 is blocked on the host, and the tool says so.
- No blacklist checks, monitoring or alerts.
- DKIM discovery guesses 44 selectors: an unusual one will be missed, and a wildcard zone makes the answer unknowable (both stated).
- Two graders that disagree: C, 60 in the relay’s JSON; B, 73 on the page.
- The DKIM score takes the best key, so github.com scored 20 of 20 though four of nine keys are 1024-bit — worth 14 on the rubric.
Conclusion
Findinggithub.com graded B, 73, with a path to A; the relay’s own JSON said C, 60.
The doctor goes past pass and fail: it follows SPF to the last include, counts the limits where records quietly break, fetches MTA-STS under tight rules, prints its rubric, and hands over records it has checked against their standards, refusing to invent the ones it cannot know. On github.com it found a B with a clear route to an A. It should retire the second grade in its JSON and score DKIM by the weakest key. For STARTTLS and DANE, use internet.nl; for blacklists and monitoring, MxToolbox.