Skip to content
Open sourceSeven protocols

42Sec

Score public email security.

42Sec builds cybersecurity and privacy software. SecLens.ONE is live: seven public protocols, a 0-100 score, paste-ready DNS, and a million-domain benchmark. No account.

In short

7
Mail protocols scored
1M
Domains in the research set
0-100
Public domain score
OSS
Source on GitHub

Score the mail setup. Paste the DNS.

Neon green Merlion inside a circuit-traced shield on a black field.

42Sec

About

Security and privacy, as apps.

42Sec builds cybersecurity and privacy software. SecLens is the one that is live.

We score what a domain already publishes. SPF that authorizes the world, DMARC left on p=none, DKIM keys nobody rotated.

SecLens is open source. The scoring rules are public. Anyone can run the same checks.

42Sec PTE. LTD. is incorporated in Singapore.

Apps

What we ship.

SecLens is live. The rest of the line is cybersecurity and privacy software, not hours on a ticket.

01

Email security

SecLens scores a public domain on seven protocols. Live DNS, a 0-100 score, records to paste.

  • SPF, DMARC, DKIM, DNSSEC, MTA-STS, DANE, TLS-RPT
  • Score plus DNS to paste
  • Benchmarked on 1M domains
See SecLens
02

Cybersecurity apps

SaaS that measures the controls a domain already publishes: mail, DNS, and the public edge.

  • Public checks, not a questionnaire
  • Methods you can inspect
03

Privacy apps

Software around personal data exposure and quieter defaults. This line is in build. No named product until it ships.

  • Minimize what leaves the box
  • Ships as software
Green matrix-code tunnel used as the visual for SecLens email and DNS scoring.
Open source

seclens.one

SecLens.ONE

Email security you can inspect.

SecLens

Point it at a public domain. Get a 0-100 score and the DNS to paste.

SecLens is an open-source tool that scores a public domain's email security across SPF, DMARC, DKIM, DNSSEC, MTA-STS, DANE, and TLS-RPT. It returns a 0-100 rating, paste-ready DNS records, and a benchmark against a published Top-1M study.

Protocols checked

  • SPF
  • DMARC
  • DKIM
  • DNSSEC
  • MTA-STS
  • DANE
  • TLS-RPT
  • Seven protocols, scored 0 to 100
  • DNS records you can paste
  • Top-1M research benchmark
  • Open source on GitHub

FAQ

Questions.

What SecLens checks, how the score works, and who 42Sec is.

What is 42Sec?

42Sec PTE. LTD. builds cybersecurity and privacy apps. SecLens.ONE is the live product: an open-source scorer for public email and DNS security.

How do I check a domain's email security?

SecLens checks a public domain's email security by reading the DNS records and MTA-STS policy that domain already publishes. It scores SPF, DMARC, DKIM, DNSSEC, MTA-STS, DANE, and TLS-RPT, then returns a 0-100 rating, paste-ready DNS records, and a comparison against its Top-1M study. The web check is free and needs no account.

Which email security protocols does SecLens check?

SecLens checks seven protocols: SPF, DMARC, DKIM, DNSSEC, MTA-STS, DANE, and TLS-RPT. It scores published records and whether those records actually protect the domain, including fetching the MTA-STS HTTPS policy rather than stopping at DNS. No-mail domains that publish a Null MX are scored on a separate profile so they are not punished for missing mail infrastructure.

Does publishing DMARC stop email spoofing?

No. A DMARC record with p=none only asks receivers to report; it does not instruct them to quarantine or reject forged mail. SecLens awards DMARC points for enforcement, not presence: p=reject at 100 percent coverage scores 25, p=quarantine scores 15, and p=none scores zero. Presence without policy is decoration.

Do parked or no-mail domains need email authentication?

Yes. Domains that never send mail are still used to spoof brands. SecLens detects RFC 7505 Null MX and scores those domains on Null MX, strict SPF, DMARC reject, and DNSSEC instead of punishing missing mail infrastructure. Those four DNS controls take a parked domain out of the spoofing supply.

Is SecLens open source?

Yes. The assessment engine is published on GitHub under the Apache License 2.0, and the scoring rules are documented on seclens.one. Anyone can inspect the RFC-numbered checks, run the Go CLI locally, or reproduce the same 0-100 rating. The public web check is free, requires no account, and does not send marketing email.