Checks SPF, DKIM, DMARC and BIMI, including recommended policy levels and selectors for stronger protection.
Validates SSL issuer, expiry window, and HSTS status to reduce downgrade and man-in-the-middle risks.
Looks for DNSSEC, CAA, MTA-STS and TLS-RPT, plus improvement tips for better email transport security.