What this configuration means
Each section below is shown because the observed records match its condition. The explanations are reviewed text selected by the data, not generated from it.
DMARC enforces rejection
myfritz.net publishes p=reject. Receivers that honour DMARC refuse mail using this domain in From unless SPF or DKIM aligns. This is the strongest published posture; it depends on every legitimate sender — including third-party platforms — having an aligned path, and on aggregate reporting, which this record does not request to catch regressions.
Strict alignment is in force
DKIM alignment is set to strict, so an authenticated identity must match myfritz.net exactly rather than sharing its organizational domain. Subdomain senders and platform-signed mail fail unless configured for the exact domain. Strict mode is deliberate and rare; it signals a tightly controlled sending estate.
SPF ends in soft fail
Unlisted sources produce softfail: receivers are asked to accept but mark the message. Under DMARC a softfail counts as an SPF failure, so the practical protection comes from DMARC policy rather than from ~all itself. Moving to -all is appropriate once the sender inventory is confirmed complete.
No common DKIM selectors found
None of the selector names commonly used by major platforms resolve under _domainkey.myfritz.net. DKIM has no enumeration mechanism, so the domain may sign with a selector this check does not try; absence here is not proof that DKIM is unused. It does mean no platform with a conventional selector is publicly visible.
No transport-security policy
myfritz.net does not publish MTA-STS, so senders negotiate TLS opportunistically and fall back to clear text if an attacker strips the upgrade. Publishing TLS-RPT first, then MTA-STS in testing mode, adds transport protection for inbound mail without risk to delivery.
BIMI record present
A BIMI record is published at default._bimi.myfritz.net. Logo display additionally requires an enforcing DMARC policy — which this domain has and, at most providers, a verified mark certificate.
Change history
No change has been observed since the first snapshot on 2026-10-03. The domain is re-checked regularly and a new entry appears here when any record above changes.
How to read this report
The grade summarizes two records only: A means an enforcing DMARC policy with SPF hard fail; B enforcing DMARC with SPF; C monitoring-only DMARC or a weak SPF qualifier; D one of SPF or DMARC missing; F neither published. It is a prioritization aid for the public control plane, not a statement about deliverability, reputation or the security of the organization behind the domain.
DMARC policy is discovered with the RFC 9989 DNS tree walk, so a subdomain with no record of its own is reported with the organizational policy it inherits. DKIM selectors are discovered from common names only; a domain may sign with selectors this check does not try. Everything on this page comes from public DNS as observed on 2026-10-04; caches and split-horizon DNS can show different values elsewhere.
If you operate myfritz.net and want a record corrected or the report removed, contact Mailybox.