~/d/hey.com

// hey.com

Live audit across 8 checks. Cached 24h · generated less than a minute ago.

domain_grade
B
good
77
/ 100 · across 8 checks
// points lost on:
dmarc −10 spf −5 security headers −5 dnssec −3
[ save & monitor ]
SSL Certificate
[ OK ]
Valid for 59 more days.
Issued by WE1 · 59 days left · TLSv1.3
→ open SSL Certificate tool
DMARC Policy
[ WARN ]
Quarantine policy. Spoofed mail goes to spam. Consider moving to 'reject' for stronger protection.
v=DMARC1; p=quarantine; adkim=s; aspf=r; ri=3600; fo=1;
→ open DMARC Policy tool
SPF Record
[ WARN ]
Soft fail (~all). Unauthorized senders flagged but not rejected. Consider -all for stronger protection.
1 lookups · all=~all
→ open SPF Record tool
MX Records
[ OK ]
MX configured (1 record(s)).
10 home-mx.app.hey.com
→ open MX Records tool
Name Servers
[ OK ]
2 authoritative nameservers
merlin.ns.cloudflare.com · serena.ns.cloudflare.com
WHOIS
[ OK ]
Valid for 159 more days.
Registrar: Cloudflare, Inc. · expires 2026-09-27
→ open WHOIS tool
Security Headers
[ WARN ]
Decent but improvable (78/100) — missing: Permissions-Policy
Score 78/100
→ open Security Headers tool
DNSSEC
[ WARN ]
No DNSSEC — domain is not signed.
Not signed
→ open DNSSEC tool
[ embed_grade_badge ]
grade badge
Domain grade: B — good
markdown (github readme)
[![DomBrains grade](https://dombrains.com/badge/hey.com/grade.svg)](https://dombrains.com/d/hey.com)
html (any webpage)
<a href="https://dombrains.com/d/hey.com"><img src="https://dombrains.com/badge/hey.com/grade.svg" alt="DomBrains grade: B"></a>
// re-queries our scoring engine · cached 1h at the edge · backlinks to this profile page
[ per_check_badges ]
ssl badge <img src="https://dombrains.com/badge/hey.com/ssl">
dmarc badge <img src="https://dombrains.com/badge/hey.com/dmarc">
spf badge <img src="https://dombrains.com/badge/hey.com/spf">
mx badge <img src="https://dombrains.com/badge/hey.com/mx">
dnssec badge <img src="https://dombrains.com/badge/hey.com/dnssec">
security_headers badge <img src="https://dombrains.com/badge/hey.com/security_headers">
// Snapshot freshness: this page is cached 24h. To force a re-scan, run any tool above with the same domain — that always queries live.