What this configuration means
Each section below is shown because the observed records match its condition. The explanations are reviewed text selected by the data, not generated from it.
DMARC requests quarantine
office.com asks receivers to quarantine mail that fails alignment. Unaligned mail is routed to spam rather than refused, which limits the damage from spoofing while leaving a margin for misconfigured legitimate senders. The usual next step is p=reject after confirming through aggregate reports that no legitimate source still fails.
No SPF record
office.com publishes no v=spf1 record, so receivers cannot evaluate whether a connecting server is authorized to use the domain as the envelope sender. Since the domain does not appear to receive mail either, the appropriate record is the null-sender policy v=spf1 -all, which makes the domain unusable for spoofing at the SPF layer.
No MX record
office.com publishes no mail exchanger. Under RFC 5321 a sender may fall back to the domain’s A or AAAA address and attempt SMTP delivery there, which usually reaches a web server that does not speak SMTP. If the domain is not meant to receive mail, a Null MX record (RFC 7505) tells senders so immediately.
No common DKIM selectors found
None of the selector names commonly used by major platforms resolve under _domainkey.office.com. DKIM has no enumeration mechanism, so the domain may sign with a selector this check does not try; absence here is not proof that DKIM is unused. It does mean no platform with a conventional selector is publicly visible.
MTA-STS is published
office.com declares a transport-security policy in testing mode. Senders report failures without refusing delivery, which is the recommended stage before enforcement. TLS-RPT is not published, so failures against the policy would go unreported.
Change history
No change has been observed since the first snapshot on 2026-09-21. The domain is re-checked regularly and a new entry appears here when any record above changes.
How to read this report
The grade summarizes two records only: A means an enforcing DMARC policy with SPF hard fail; B enforcing DMARC with SPF; C monitoring-only DMARC or a weak SPF qualifier; D one of SPF or DMARC missing; F neither published. It is a prioritization aid for the public control plane, not a statement about deliverability, reputation or the security of the organization behind the domain.
DMARC policy is discovered with the RFC 9989 DNS tree walk, so a subdomain with no record of its own is reported with the organizational policy it inherits. DKIM selectors are discovered from common names only; a domain may sign with selectors this check does not try. Everything on this page comes from public DNS as observed on 2026-09-22; caches and split-horizon DNS can show different values elsewhere.
If you operate office.com and want a record corrected or the report removed, contact Mailybox.