Security

At RacterMX, security is our top priority. We implement multiple layers of protection to keep your email communications secure and maintain the highest standards of email authentication and encryption.

Compliance & Certifications

GDPR Compliant SOC 2 Type II HIPAA Ready RFC Compliant

Email Authentication

SPF (Sender Policy Framework)

βœ“ STRICT - The Iron Gate

We use the strictest SPF policy (-all) telling the world: "If it's not on this list, it's NOT us. Reject it." This is the strongest deliverability signal you can send to major providers.

SPF validates that emails come from authorized mail servers, preventing email spoofing and impersonation.

v=spf1 ip4:82.221.100.161 -all

DNS Lookups: 0/10 - Lean and efficient, well within the 10-lookup limit for fast validation.

DKIM (DomainKeys Identified Mail)

πŸš€ ELITE - ED25519 256-bit

We use Edwards-curve cryptography (ED25519)β€”the future of email authentication. It's faster, smaller, and mathematically stronger than RSA. We maintain RSA fallback for older servers.

All emails are cryptographically signed to verify sender authenticity and ensure messages haven't been tampered with in transit.

DMARC (Domain-based Message Authentication)

πŸ“‚ QUARANTINE Policy

Suspicious mail is sent to the spam folder, protecting the inbox while maintaining brand association. We use strict alignment (aspf=s; adkim=s) requiring exact domain matching for maximum security.

DMARC provides reporting and policy enforcement for email authentication, combining SPF and DKIM validation.

v=DMARC1; p=quarantine; adkim=s; aspf=s;

Transport Security

TLS Encryption

βœ“ TLS 1.3 Supported

All mail servers support the latest TLS 1.3 protocol with AES-256-GCM encryption for secure email transmission.

We enforce TLS encryption for all email transmission to prevent man-in-the-middle attacks.

MTA-STS (Mail Transfer Agent Strict Transport Security)

βœ“ ENFORCE Mode

MTA-STS enforces TLS encryption and prevents downgrade attacks. Our policy is set to enforce mode with 7-day caching.

MTA-STS ensures that email is only delivered over encrypted connections, protecting against active attacks.

DANE/TLSA

πŸ” CERTIFICATE FORTRESS - Elite 0.1%

DANE enabled with certificate pinning to DNS. Even if a Certificate Authority is compromised, attackers cannot forge our identity. You are protected by cryptographic proof.

DANE (DNS-based Authentication of Named Entities) provides the highest level of transport security by cryptographically binding our mail server's certificate to DNS.

Monitoring & Reporting

TLS-RPT (TLS Reporting)

βœ“ Enabled

We receive detailed reports about TLS connection failures, allowing us to quickly identify and resolve encryption issues.

v=TLSRPTv1; rua=mailto:admin@racter.com

RBL (Real-time Blackhole List) Status

βœ“ Clean - Not Blacklisted

Our mail servers (mail.racter.com at 82.221.100.161) maintain a clean reputation across all major blacklist databases.

DNS Security

DNSSEC

βœ“ Enabled

DNSSEC is properly configured, providing cryptographic authentication of DNS records and preventing DNS spoofing attacks.

PTR Records (Reverse DNS)

βœ“ Configured

Reverse DNS properly configured: 82.221.100.161 β†’ mail.racter.com. This proves mail server legitimacy and improves deliverability.

CAA Records

Certificate Authority Authorization records restrict which CAs can issue certificates for our domains:

Infrastructure Security

Data Privacy

Responsible Disclosure

If you discover a security vulnerability, please report it to us immediately. We appreciate responsible disclosure and will work with you to address any issues promptly.

Contact: security@ractermx.com

Security Scan

Want to check your own domain's email security? Use our free domain scanner at scan.ractermx.com to get a comprehensive security report.