Measurement estimates from a single vantage point — not a compliance certification. Guidance below is for operators, not an SLA.
DNS
Dual-stack
[2] 6/6/6 [O]
Meaning: Shows how many authoritative name servers exist, and how many IPv6 endpoints are configured, responsive, and operational.
IPv4 6/6/6 · IPv6 6/6/6 · location O
| Host | IPv4 | IPv6 | Probes |
norman.ns.cloudflare.com [O] |
172.64.33.217, 108.162.193.217, 173.245.59.217 |
2a06:98c1:50::ac40:21d9, 2803:f800:50::6ca2:c1d9, 2606:4700:58::adf5:3bd9 |
ipv4 172.64.33.217 ok; ipv4 108.162.193.217 ok; ipv4 173.245.59.217 ok; ipv6 2a06:98c1:50::ac40:21d9 ok; ipv6 2803:f800:50::6ca2:c1d9 ok; ipv6 2606:4700:58::adf5:3bd9 ok; |
kami.ns.cloudflare.com [O] |
108.162.192.177, 173.245.58.177, 172.64.32.177 |
2a06:98c1:50::ac40:20b1, 2803:f800:50::6ca2:c0b1, 2606:4700:50::adf5:3ab1 |
ipv4 108.162.192.177 ok; ipv4 173.245.58.177 ok; ipv4 172.64.32.177 ok; ipv6 2a06:98c1:50::ac40:20b1 ok; ipv6 2803:f800:50::6ca2:c0b1 ok; ipv6 2606:4700:50::adf5:3ab1 ok; |
Mail
Dual-stack
[1 MX] v4 smtp 4/4/4 v6 smtp 4/4/4 [O]
Meaning: Shows MX footprint and SMTP health per IP family. Operational means an SMTP banner and EHLO exchange succeeded on port 25.
IPv4 SMTP 4/4/4 · IPv6 4/4/4 · location O
| Host | IPv4 | IPv6 | Probes |
opm-gov-jm.mail.protection.outlook.com [O] |
52.101.50.1, 52.101.41.180, 40.93.192.1, 52.101.60.182 |
2a01:111:f403:f907::1, 2a01:111:f403:f805::1, 2a01:111:f403:f909::d, 2a01:111:f403:c918::3 |
ipv4 52.101.50.1 ok; ipv4 52.101.41.180 ok; ipv4 40.93.192.1 ok; ipv4 52.101.60.182 ok; ipv6 2a01:111:f403:f907::1 ok; ipv6 2a01:111:f403:f805::1 ok; ipv6 2a01:111:f403:f909::d ok; ipv6 2a01:111:f403:c918::3 ok; |
Web
Dual-stack
[1] 2/2/2 [I]
Meaning: Shows IPv6 web endpoint readiness for the discovered HTTPS host. Operational means family-specific HTTPS requests complete successfully.
IPv4 2/2/2 · IPv6 2/2/2 · location I
| Host | IPv4 | IPv6 | Probes |
opm.gov.jm [I] |
104.21.22.186, 172.67.206.158 |
2606:4700:3031::6815:16ba, 2606:4700:3036::ac43:ce9e |
ipv4 ok; ipv6 ok; |
DNSSEC
Unsigned
U/-/-
Meaning: Shows whether DNSKEY data is observed at the apex (signed), absent (unsigned), or unavailable due to lookup error.
Apex DNSKEY presence only — not full chain validation.
Analyze on DNSViz
📌 Action item(s):
- Enable DNSSEC signing and publish a DNSKEY at the apex. Use DNSViz to validate the full chain.
DMARC
p=none
p=none — published organizational policy. Monitoring only (receivers should not reject mail); tighten toward quarantine, then reject when ready. Not the same as missing DMARC.
Meaning: Published DMARC policy at _dmarc.opm.gov.jm (DNS TXT). Shows organizational policy (p=) and subdomain policy (sp=) when set.
Record at _dmarc.opm.gov.jm:
v=DMARC1; p=none; rua=mailto:60aeccab89a0461e821d1b218535a23d@dmarc-reports.cloudflare.net
Policy publication only — SPF/DKIM not measured. Not part of the 0–4 row score.
Check on dmarcian
📌 Action item(s):
- DMARC is monitoring-only (p=none). Move toward quarantine, then reject. Review on dmarcian.