KorantixKorantix
Free guides

Understand what your scan results mean

Short, practical explainers for the records and checks Korantix reports on β€” written for the person who has to fix the finding, not just read it.

What is SPF, and why does β€œ~all” vs β€œ-all” matter?SPF tells receiving mail servers which servers are allowed to send email for your domain. The difference between a soft-fail and a hard-fail policy decides whether a forged email gets flagged β€” or rejected outright.DMARC in plain terms: policy, alignment, and reportsDMARC ties SPF and DKIM together and tells receivers what to do when a message fails both β€” and, if you ask it to, sends you a daily report of who's sending mail as your domain.DKIM and why β€œno selector known” isn't the same as β€œmissing”DKIM signs your outgoing email with a private key so receivers can verify it wasn't altered in transit β€” but unlike SPF and DMARC, there's no single well-known place to look for it.SSL/TLS certificate chains and why expiry catches people off guardA certificate doesn't just need to be valid β€” it needs a complete, trusted chain back to a root your visitor's browser already trusts. Here's how that chain works, and why an expiry date sneaks up on almost everyone.MX records explained: how email actually gets routed to youAn MX record is what tells the entire internet which server should receive email for your domain. Get the priority values wrong, or leave a stale one in place, and mail either fails silently or goes to the wrong place.DNSSEC: what it actually protects against (and what it doesn't)DNSSEC stops an attacker from forging DNS answers in transit β€” it does not encrypt anything, and it does not protect the DNS query itself from being seen. Knowing the difference matters for deciding whether it's worth deploying.MTA-STS: forcing encrypted mail delivery, and why SMTP needed itUnlike a browser connecting over HTTPS, an SMTP server delivering your email has historically had no reliable way to insist on an encrypted connection β€” MTA-STS is the record that closes that gap.STARTTLS vs implicit TLS: two different ways mail gets encryptedBoth approaches end with an encrypted connection, but they start very differently β€” and the difference explains why the same misconfiguration doesn't affect them the same way.BIMI: getting your logo to actually show up next to your emailsBIMI is the record that lets your verified brand logo appear in a recipient's inbox next to your emails β€” but it has a real prerequisite most people miss: strong DMARC enforcement first.A practical guide to reading email headers without getting lostRaw email headers look like noise, but they follow a consistent structure once you know what to look for β€” here's the order to read them in, and which parts actually matter for troubleshooting.RDAP vs WHOIS: what changed, and why the switch happenedWHOIS has been the standard way to look up domain registration info for decades β€” RDAP is quietly replacing it, and the reasons are less about nostalgia and more about a protocol that was never designed for how the internet uses it today.