Audits email authentication over DNS-over-HTTPS (Cloudflare, Google or Quad9): SPF syntax, every include/redirect resolved recursively with the RFC 7208 ten-lookup count, +all/?all/ptr warnings and duplicate records; DKIM keys for the selectors you enter plus twenty common provider selectors, with RSA key size read from the DER key, Ed25519 support and revoked/testing flags; DMARC policy, subdomain policy, pct, alignment and report addresses with effective-policy explanation. Everything is scored 0–100 with concrete recommendations; the full audit is available as JSON. Names are sent to the chosen resolver; nothing is stored.