How Korantix checks a domain
What each scan looks at, where the evidence comes from, how the score is calculated — and what a public scan cannot prove.
Last reviewed: 2026-09-30
Where the evidence comes from
Every check uses public information that anyone could observe: DNS answers (queried live from Korantix's servers), the TLS certificate your web server presents, the SMTP greeting and STARTTLS offer of your mail servers, registry RDAP data and public DNS blocklists (queried over DNS-over-HTTPS). Korantix never asks for passwords, mailbox access or admin rights, and does not send email.
What is checked
- Email: SPF (syntax, qualifier, number of DNS lookups), DMARC (presence, policy, pct, reporting), DKIM (when you give the selector your provider uses — without it, DKIM is reported as not checked, never as missing), MTA-STS, TLS-RPT and BIMI.
- DNS: MX, NS, SOA, CAA and DNSSEC.
- Mail server: port 25 reachability of MX hosts, STARTTLS support and the mail server certificate (only when the network path allows it).
- TLS: the website certificate — validity, expiry, issuer, hostname match; DANE/TLSA where published.
- Reputation: listing of the mail server IPs on public DNS blocklists, reported separately from the score.
How the score is calculated
The score starts at 100. Each observed weakness deducts points; the heaviest deductions are for problems that let someone send mail as you or break delivery (missing SPF or DMARC, permissive SPF, an invalid certificate). Informational signals such as TLS-RPT, BIMI or reverse DNS never lower the score.
Area scores are a separate, transparent view: each area starts at 100 and loses 25 points per critical and 8 per warning finding in that area. The score version is shown with every result, so two scans are comparable only when their versions match.
Unmeasured is not failed
When a check cannot be performed — a blocked port, a timeout, an unreachable resolver — the result says so and no points are deducted. Korantix does not infer a result it did not observe.
What a public scan cannot prove
- It cannot see inside your mail platform (rules, forwarding, user accounts).
- It cannot confirm that every legitimate sender is covered by SPF/DKIM — only you know your senders; DMARC reports show them.
- A good score does not mean a domain is immune to phishing or compromise; it means the published controls are configured well.
- Blocklist results depend on the lists queried; Korantix shows which lists were checked.
Privacy
Scan results are shown to you and are not published as web pages; they are never indexed by search engines. Header Analyzer input stays in your browser. Details are on the Privacy page.