Checks SPF, DKIM, DMARC and BIMI — including recommended policy levels and selectors for stronger protection.
Validates SSL issuer, expiry window, and HSTS status to reduce downgrade and man-in-the-middle risks.
Checks DNSSEC, CAA, MTA-STS and TLS-RPT — plus improvement suggestions for better email transport security.