Here's how 21k.de protects its email
Checked August 02, 2026 02:47
Inbound mail for this domain is handled by Microsoft 365.
Core protections
SPF
ProtectedA strict SPF policy is in place — servers not on the approved list are rejected outright.
Show raw DNS record
v=spf1 include:secureserver.net -all
DKIM
Not configuredNo DKIM signing key was found under any common selector. Recipients have no way to verify a message wasn't altered in transit.
Show raw DNS record
No record found.
DMARC
PartialDMARC is present but not set to reject, so mail that fails alignment may still be delivered or only flagged.
- Aggregate reports are configured, so the domain owner gets visibility into who's sending on their behalf.
Show raw DNS record
v=DMARC1; p=quarantine; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net;
Advanced protections
| Protection | Status |
|---|---|
| MTA-STS | Not found |
| TLS-RPT | Not found |
| DNSSEC | Not found |
| BIMI | Not found |
| CAA | Not found |
Recommendation
What we'd fix first for 21k.de
- No DKIM signing key was found, so outgoing mail can't be verified as genuinely from this domain.
- DMARC isn't set to reject failing mail, so spoofed messages may still reach an inbox.
Want this level of protection for your own attachments?
Adlerwacht adds passkey-verified, end-to-end secured delivery on top of whatever your domain already has configured.
What do these mean?
What is SPF?
SPF (Sender Policy Framework) is a DNS record listing which mail servers are allowed to send email for a domain. Without it, anyone can forge the "From" address.
What is DKIM?
DKIM (DomainKeys Identified Mail) cryptographically signs outgoing email, letting the receiving server verify it wasn't altered in transit and really came from this domain.
What is DMARC?
DMARC tells receiving mail servers what to do with messages that fail SPF or DKIM checks — ignore them, quarantine them, or reject them outright.
What is MTA-STS?
MTA-STS forces incoming mail to this domain to travel over an encrypted, certificate-verified connection, closing off a common way attackers intercept mail in transit.
What is CAA?
A CAA record lists which Certificate Authorities are allowed to issue TLS certificates for a domain, making it harder for an attacker to get a fraudulent certificate issued elsewhere.