nonexistent-domain-test-xyz.example

D-
Trust rating
Weak · 61/100
Procurement snapshot
1 critical finding identified — these point to architectural gaps, not just configuration tweaks.
Strengths
MX Records & Mail Provider
Known Breaches
CVE Exposure
Questions to ask
Confirm email authentication (SPF/DKIM/DMARC) rollout plans
Sign in to see 2 more
Estimated remediation effort: 2–6 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change 1 scan · Last scanned July 11, 2026
Score
100 75 50 25 0
D-
nonexistent-domain-test-xyz.example
61/100
Compliance & Certifications
Not yet verified
SOC 2 TYPE II
SOC 2 Type II
Audit report not on file
3rd party · AICPA
ISO 27001
ISO 27001
Certificate not on file
3rd party · accredited body
GDPR
GDPR
DPA not on file
Self-reported
CCPA
CCPA
Privacy policy not on file
Self-reported
Incident History
No public breaches on record
Security Posture
5 items need attention
3 passed
0 of 1 fixed
All 1 critical issue marked as fixed
Re-scan to confirm and update your score.
Turn on email authentication (SPF, DKIM, DMARC)
DMARC / Email Security
1–2 days Critical

This exposes customers, partners, and employees to phishing attacks that impersonate your brand. Right now, anyone can send an email that looks like it came from [email protected] — no password or hack required. This is how the vast majority of phishing scams that impersonate a company work, and it can damage your reputation with customers even though your systems were never touched. Missing: DMARC, SPF.

NIST SP 800-177r1§4
Trustworthy Email recommends SPF, DKIM and DMARC for every email domain
ISO 27001:2022A.5.14
Information transfer controls cover email
CISA BOD 18-01DMARC
Requires DMARC p=reject on US federal email domains
How to fix this
1Add an SPF record in your domain's DNS settings (check with whoever manages your website or domain registration). This is a line of text that tells other mail servers which servers are allowed to send email as you.
v=spf1 include:_spf.google.com ~all
v=DMARC1; p=quarantine; rua=mailto:[email protected]
2Not sure which value to use? Search "[your email provider] SPF record" (e.g. "Google Workspace SPF record") — every provider publishes the exact line to use.
3If DKIM signing isn't on yet (we can't confirm it from outside): Turn on DKIM signing — look for "DKIM" under your email provider's admin/security settings. It gives you a record to add in your domain's DNS settings (check with whoever manages your website or domain registration).
4Add a DMARC record in your domain's DNS settings (check with whoever manages your website or domain registration). This tells receiving mail servers what to do with messages that fail SPF and DKIM checks (start on "quarantine" — send to spam — rather than "reject", so nothing legitimate gets blocked while you're testing).
5After 2–4 weeks, check the DMARC reports for anything legitimate that got flagged, then tighten the policy from quarantine to reject.
Report unlocked.
View all 3 passed checks
MX Records & Mail Provider
Known Breaches
CVE Exposure
Couldn't check: TLS Protocol Support, TLS Configuration, Malware / Phishing Blocklist, HSTS Header, Security Headers, Cookie Security, Certificate Hygiene — the check didn't complete (the site blocked or timed out our scanner, or a data source was unavailable), so these aren't counted in the score.
Company Signals
Operational risk
Last funding
Employees
Trust Resources
Claim profile →
Trust Center
Not detected
Privacy Policy
DPA (Data Processing Agreement)
Subprocessors List
Similar companies
Appears in
Vendors graded D
832 companies · LynxRadar ranking