How Is the Domain Score of Domain Scanner Calculated?
The score for Domain Scanner is calculated based on several critical email security and DNS configurations, including:
1. SPF Record
- ✅ Exists: If the domain has a valid SPF (Sender Policy Framework) record, points are awarded.
- ⚠️ Weak Configuration: Points may be deducted if the SPF is misconfigured (e.g., multiple include statements with no -all or ~all, or missing authorized senders).
2. DKIM Record
- ✅ Published and Active: Points are given if the DKIM (DomainKeys Identified Mail) record is properly published.
- ❌ Missing or Inactive: If no valid DKIM record is found, the domain loses points.
Important: Our system initially checks our internal DKIM database for results. If you’ve only recently added EasyDMARC’s RUA and RUF addresses to your DMARC record, the displayed data may not yet be fully accurate. To ensure more reliable and detailed DKIM results, some aggregate reports need to be received first.
3. DMARC Record
- ✅ Exists with Proper Policy: Having a DMARC record with an enforcement policy (e.g., quarantine or reject) contributes positively to the score.
- ⚠️ None Policy or Misconfigured: Domains with p=none or other issues receive a lower score.
4. BIMI Record
- ✅ Published: While optional, a BIMI (Brand Indicators for Message Identification) record shows a higher level of security and branding.
- ❌ Not Published: No penalty, but you’ll miss out on potential score gains.
Note: If you prefer not to include BIMI in your score calculation, you can disable it using the toggle at the top left corner.
How to Improve Your Domain Score
- Set up a valid SPF record
→ Use EasyDMARC’s SPF Generator or validator to check and correct your current record. - Publish and activate DKIM
→ Ensure DKIM records are added in DNS and enabled from your email provider’s side. - Configure a strong DMARC policy
→ Start with p=none, monitor reports, and move to quarantine or reject when ready. - Add a BIMI record
→ Not required, but recommended for brand visibility and trust.
The Domain Score in EasyDMARC is more than just a number, it's a clear indicator of how well your domain is protected from phishing, spoofing, and abuse. It helps you identify gaps and provides actionable steps to improve your domain’s security posture.
By using the Domain Scanner regularly and following the recommended best practices, you can ensure that your emails are trusted, secure, and fully compliant.
Need help interpreting your Domain Score or improving your domain’s configuration? Reach out to EasyDMARC Support.