Security Analysis
moe.gov.ae
D
105 / 225
3 critical3 high3 medium
Basic Security
0/40 (0%)DNSSEC Enabledhigh
DNSSEC protects against DNS spoofing and cache poisoning
→ Enable DNSSEC to protect against DNS spoofing and cache poisoning attacks. Contact your domain registrar to enable DNSSEC.
Multiple Nameserversmedium
Multiple nameservers provide redundancy
→ Only 1 nameserver(s) found. Configure at least 2 nameservers for redundancy and fault tolerance.
Nameserver Diversitylow
Nameservers on different networks improve resilience
→ All nameservers appear to be from the same provider. Consider using nameservers from different providers for better resilience.
Record Security
15/55 (27%)CAA Recordshigh
CAA restricts which CAs can issue certificates
→ Add CAA records to specify which Certificate Authorities are allowed to issue certificates for your domain. Example: 0 issue "letsencrypt.org"
SPF Record
SPF prevents email spoofing
DMARC Recordcritical
DMARC protects against phishing
→ Add a DMARC record at _dmarc.yourdomain.com. Example: v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com
DKIM Presencehigh
DKIM signs outgoing emails
→ DKIM could not be detected from standard TXT records. Ensure DKIM is configured with your email provider. Records are typically at selector._domainkey.yourdomain.com
Advanced Security
15/25 (60%)Mail Server Configurationmedium
Multiple MX records provide email redundancy
→ Consider adding a backup MX record for email redundancy.
SOA Record Configuration
SOA record with reasonable TTL/refresh values
IPv6 Supportlow
AAAA records enable IPv6 connectivity
→ No IPv6 (AAAA) records found. Consider adding IPv6 support for future-proofing.
Domain Reputation
20/50 (40%)Typosquatting Check
Domain does not mimic protected brands
Domain Blacklist Statuscritical
Domain checked against spam and malware blacklists (Spamhaus DBL, SURBL, URIBL)
→ Domain is listed on 1 blacklist(s): Spamhaus DBL. Contact the blacklist operators to request removal.
IP Blacklist Statusmedium
Server IP addresses checked against spam and abuse blacklists (Spamhaus ZEN, SpamCop, Barracuda)
→ IP address(es) listed on blacklists: 5.195.26.49 (Spamhaus ZEN). This may indicate the IP was used for spam or is on a shared hosting platform.
Reputation Confidence Alertcritical
Aggregate confidence score from multiple blacklist sources
→ High confidence (64%) that this domain/IP may be associated with malicious activity. Review blacklist details and take action.
Threat Detection
55/55 (100%)DGA Detection
Domain Generation Algorithm detection
DNS Tunneling Detection
Detection of data exfiltration via DNS
Fast-Flux Detection
Detection of rapidly changing DNS infrastructure
Domain Age Check
Detection of newly registered domains