Skip to content
Permanent methodology version

Public email score v4

Published on 30.09.2026. This URL permanently describes the assessment basis of stored results and is not retrospectively reinterpreted.

Binding principles

  1. Only email DNS, email authentication and mail transport protection contribute to the score, rating and coverage. Their weights are 20:25:15, normalized to 100 percent.
  2. Website TLS, web security headers, blocklists, reputation and website availability are additional information and do not affect the email assessment.
  3. Unknown and not applicable results never count as passed. A rating requires at least 50 percent weighted email coverage.
  4. Weekly and monthly summaries require at least 75 percent email coverage and six assessed email signals. Stored findings from older scans are re-evaluated without network requests.
  5. Public checks use public DNS and limited, validated, IP-pinned HTTPS on port 443. No anonymous SMTP checks or mailbox access.
  6. The score is a technical snapshot, not a certificate, legal assessment or a promise of delivery or inbox placement.
  7. DANE has high priority: missing usable DNSSEC-authenticated TLSA records for any MX, or an insecure DNSSEC chain, deducts 8 points once. The rating is capped at BBB, excluding A grades. Invalid DANE data also remains a critical finding.
  8. When a usable DANE policy is published at every MX, there is no MTA-STS deduction. Missing MTA-STS, mode: none or testing mode produces a recommendation for additional coverage of senders without DANE. Without this DANE evidence, missing MTA-STS, mode: none or mode: testing deducts 3 points once. Only a valid policy with mode: enforce enforces MTA-STS protection.
  9. Fixed deductions apply once after the weighted base score. Missing policies and MTA-STS testing mode do not also lower the category through their status. Invalid policies remain separate findings. The rating cap applies independently of points, for example 92/100 with a maximum of BBB.
  10. Uncertain DANE evidence does not incur a missing-DANE deduction. It reduces coverage and caps the rating at A. Proven absence of enforcing MTA-STS protection still incurs the MTA-STS deduction. Older snapshots need a new one-off check to assess DANE; their original measurement time is preserved.
  11. The public DANE check assesses the DNSSEC-authenticated MX set and TLSA at every MX target. It confirms published transport policies, without matching the current SMTP certificate. A valid null MX needs no inbound DANE or MTA-STS policy.
  12. MTA-STS does not override a DANE error. It is an alternative when DANE is absent and can additionally protect senders without DANE.
  13. Priority follows BSI TR-03108 and BSI-CS155. Points and rating caps are Sendequelle rules, not a BSI grading scale or evidence of conformity.

Version status

Profile
public-email-trust-v4
Status
current
Check profiles
6
Published
30.09.2026

Technical sources

Included tools

Check blocklists

Checker
1.0.0
Scope
Public DNS and IP-pinned HTTPS to the configured provider
References
Transparent provider sources and their respective terms of use
Open tool

Check DMARC

Checker
1.0.0
Scope
DNS
References
RFC 7489, RFC 9989, RFC 9990
Open tool

Check MX and DNS

Checker
3.0.0
Scope
DNS
References
RFC 1034, RFC 1035, RFC 7505
Open tool

Check MTA-STS

Checker
1.0.0
Scope
DNS and IP-pinned HTTPS on port 443
References
RFC 8461
Open tool

Check your domain

Start without signing in. History and alerting require a verified domain and an available account.