Changelog

User-visible changes: new and improved checks, scoring changes, features and documentation updates across the domain scanner, the two live email tests (sender and receiver) and Record Studio. The domain scan runs 108 individual checks across six modules – every one explained on the checks & scoring page; the live sender and receiver tests add deep, message-level checks (SPF/DKIM/DMARC/ARC, S/MIME, STARTTLS/DANE/MTA-STS and more), and a single email can now cover both directions. Dates are deployment dates.

– Record Studio verifies HTTP(S) records over IPv4 and IPv6

– TLSA generator reads the certificate over IPv4 and IPv6

– IPv6 in zone-transfer and name-server-distribution checks

– Full IPv6 coverage for address-based checks

– More precise MTA-STS diagnostics

– New visual design

– Structured reports for the sender and receiver tests

– Service headings on the results page & pointer to the live mail tests

– Clearer report: triage list, service groups and plain-language subtitles

– Test the receiving side straight from the sender test — no second email

– The receiver test now also analyses the message you send

– S/MIME signature & SMIMEA verification (sender test)

– Fix: a SHA-1 root is no longer flagged in the MX chain (receiver test)

– Public-CA trust of the MX certificate (receiver test)

– Delivery-path trace (sender test) & reverse-DNS check (receiver test)

– ARC chain verification (sender test)

– MIME structure checks (sender test)

– MTA-STS enforcement simulation, TLS-RPT (receiver) and one-click unsubscribe (sender)

– DNSSEC status of auth records and bounce-address deliverability (sender test)

– SPF record hygiene checks (sender test)

– DMARC external-report authorization and DKIM configuration hints (sender test)

– Weak DKIM-key screening and a DMARC reporting check (sender test)

– Certificate-chain drilldown (receiver) and HELO-SPF + reverse-DNS checks (sender)

– DANE verification for the receiver test, plus more sender message-hygiene checks

– Sender & receiver tests: much deeper TLS, certificate and authentication analysis

– Receiver test: more accurate grading and clearer messages

– New: email receiver test (does mail reach your MX?)

– Record Studio: safer keys, more correct records, honest “load” warnings

– Mail send-test: more accurate verdicts and clearer errors

– CAA: Signed HTTP Exchanges (cansignhttpexchanges)

– Record generators: the validity summary now stays put

– CAA generator: one consistent output

– CAA generator: sortable output

– security.txt generator: phone contacts fixed

– CAA generator: correct contact-phone format

– Smoother on phones: no sideways scrolling, bigger tap targets

– Weak-key screening and a full-chain signature check

– CAA contact properties, and sharper certificate lifetime & hostname checks

– CAA: RFC 8657 account and validation-method binding

– SPF generator: Atlassian and SAP Cloud added

– SPF generator: CodeTwo Email Signatures

– New scanner IPv6 address

– Record Studio: Enter loads the record

– Deep BIMI validation in the domain check and the sender test

– VMC certificates are now cryptographically verified

– BIMI without a mark certificate (VMC) is now a warning

– Record Studio: preview your BIMI logo

– New: Email sender test (MailFrom)

– Accuracy pass across DNSSEC, DANE, mail and header checks

– Simpler tool names in Record Studio

– “Record generators” is now “Record Studio”

– CAA generator: Certigna removed (no longer issues public TLS)

– CAA generator: many more certificate authorities, now searchable

– CAA generator grid is now a table with row separators

– CAA generator: per-CA critical-flag selector

– CAA generator rebuilt as a per-CA issue / issuewild / issuemail grid

– Docs: CAA for S/MIME (issuemail)

– CAA generator: restrict S/MIME certificate issuers (issuemail)

– Generator lists sorted & polished

– Scan identifies newsletter / marketing ESPs on sending subdomains

– SPF generator: add sending-service includes with a click

– SPF generator: 20 more mail providers recognised

– CAA generator: more certificate authorities

– Validity check & details when you load a record — now for every generator

– TLSA generator: certificate details shown under each matching record

– TLSA & SMIMEA generators: certificate details when you load a record

– TLSA & SMIMEA generators: colour-coded validity when you load a record

– SMIMEA generator: 3 0 0 default, and “Load current record” now fills the form

– New: SMIMEA record generator (DANE for S/MIME)

– Each record generator now has its own page

– SPF/DMARC/TLS-RPT generators: warn on multiple published records

– TLSA generator: choose among multiple published records

– DANE-TA root-pin note (prefer 2 0 0)

– Robust root-CA detection (cross-signed roots)

– DNSSEC check: consistency & accuracy pass

– Mail DANE check: PKIX-TA/EE records (usage 0/1) handled per RFC 7672

– Web-DANE check: smarter handling of PKIX-TA (usage 0) records

– TLSA generator: when to pin the root vs. an intermediate (PKIX-TA vs DANE-TA)

– SPF generator now recommends softfail (~all)

– Jump from a finding straight to the matching record generator

– Your mail provider in the scan report

– Suggest the right SPF include from your mail provider

– Build a TLSA record from your live certificate

– Load your published record into the generators

– DNS record generators

– Complete German version, DMARCbis & security.txt

– Discoverability & accuracy fixes

– Anycast providers & DKIM selectors

– DNS deep checks & fewer false positives

– Mail server deep-dive & backend profiling

– RFC audit, QUIC probe & redesign

– Accuracy review & report UX

– Initial release