The overall score is a weighted total of the SPF, DKIM and DMARC results, out of 100. Every number on this page is read straight from the implementation (packages/core/src/check.ts), so changing the scoring logic changes this page with it.
| Item | Weight | How it is scored |
|---|---|---|
| SPF | 35 | Zero if no record is published, or if a syntax error or similar puts it in “Action needed”. A “Review” result earns 60% of the weight. |
| DKIM | 25 | Zero if no usable key is found. A “Review” result — a revoked or undersized key, for example — earns 60% of the weight. |
| DMARC | 40 | The policy strength sets the base, which is then scaled by the pct tag. A syntax error or an unauthorised external report destination halves it again. |
| Total | 100 |
| Policy | Multiplier | How it is scored |
|---|---|---|
| p=reject | 100% | Spoofed mail is rejected — the most effective setting |
| p=quarantine | 75% | Spoofed mail is quarantined as junk |
| p=none | 45% | Monitoring only; spoofed mail is still delivered |
When the pct tag is below 100, the result is scaled by “0.5 + pct ÷ 100 × 0.5”. At pct=100 (the default) the multiplier is unchanged.
Alongside the score, one of three verdicts is assigned.
| Verdict | Condition |
|---|---|
| Good | 80 or above, with both SPF and DMARC published |
| Review | 45 or above (including when SPF or DMARC is missing) |
| Action needed | Below 45 |
The weighting is our own, chosen to reflect how well a domain’s authentication stops spoofed mail. It is not an industry standard and not a certification by any third party.
The DKIM score only covers the selectors that could be found. DNS offers no way to list selectors, so a zero does not necessarily mean DKIM is unconfigured.
The score reflects the DNS responses at the moment of the query. Change the records and the result changes with them.