Email security
SecLens scores a public domain on seven protocols. Live DNS, a 0-100 score, records to paste.
- SPF, DMARC, DKIM, DNSSEC, MTA-STS, DANE, TLS-RPT
- Score plus DNS to paste
- Benchmarked on 1M domains
42Sec
42Sec builds cybersecurity and privacy software. SecLens.ONE is live: seven public protocols, a 0-100 score, paste-ready DNS, and a million-domain benchmark. No account.
In short
Score the mail setup. Paste the DNS.

42Sec
About
42Sec builds cybersecurity and privacy software. SecLens is the one that is live.
We score what a domain already publishes. SPF that authorizes the world, DMARC left on p=none, DKIM keys nobody rotated.
SecLens is open source. The scoring rules are public. Anyone can run the same checks.
42Sec PTE. LTD. is incorporated in Singapore.
Apps
SecLens is live. The rest of the line is cybersecurity and privacy software, not hours on a ticket.
SecLens scores a public domain on seven protocols. Live DNS, a 0-100 score, records to paste.
SaaS that measures the controls a domain already publishes: mail, DNS, and the public edge.
Software around personal data exposure and quieter defaults. This line is in build. No named product until it ships.

seclens.one
SecLens.ONE
SecLens
Point it at a public domain. Get a 0-100 score and the DNS to paste.
SecLens is an open-source tool that scores a public domain's email security across SPF, DMARC, DKIM, DNSSEC, MTA-STS, DANE, and TLS-RPT. It returns a 0-100 rating, paste-ready DNS records, and a benchmark against a published Top-1M study.
FAQ
What SecLens checks, how the score works, and who 42Sec is.
42Sec PTE. LTD. builds cybersecurity and privacy apps. SecLens.ONE is the live product: an open-source scorer for public email and DNS security.
SecLens checks a public domain's email security by reading the DNS records and MTA-STS policy that domain already publishes. It scores SPF, DMARC, DKIM, DNSSEC, MTA-STS, DANE, and TLS-RPT, then returns a 0-100 rating, paste-ready DNS records, and a comparison against its Top-1M study. The web check is free and needs no account.
SecLens checks seven protocols: SPF, DMARC, DKIM, DNSSEC, MTA-STS, DANE, and TLS-RPT. It scores published records and whether those records actually protect the domain, including fetching the MTA-STS HTTPS policy rather than stopping at DNS. No-mail domains that publish a Null MX are scored on a separate profile so they are not punished for missing mail infrastructure.
No. A DMARC record with p=none only asks receivers to report; it does not instruct them to quarantine or reject forged mail. SecLens awards DMARC points for enforcement, not presence: p=reject at 100 percent coverage scores 25, p=quarantine scores 15, and p=none scores zero. Presence without policy is decoration.
Yes. Domains that never send mail are still used to spoof brands. SecLens detects RFC 7505 Null MX and scores those domains on Null MX, strict SPF, DMARC reject, and DNSSEC instead of punishing missing mail infrastructure. Those four DNS controls take a parked domain out of the spoofing supply.
Yes. The assessment engine is published on GitHub under the Apache License 2.0, and the scoring rules are documented on seclens.one. Anyone can inspect the RFC-numbered checks, run the Go CLI locally, or reproduce the same 0-100 rating. The public web check is free, requires no account, and does not send marketing email.