Measurement estimates from a single vantage point — not a compliance certification. Guidance below is for operators, not an SLA.
DNS
Dual-stack
[3] 3/3/3 [O]
Meaning: Shows how many authoritative name servers exist, and how many IPv6 endpoints are configured, responsive, and operational.
IPv4 3/3/3 · IPv6 3/3/3 · location O
| Host | IPv4 | IPv6 | Probes |
dns3.easydns.ca [O] |
64.68.192.10 |
2620:49:1::10 |
ipv4 64.68.192.10 ok; ipv6 2620:49:1::10 ok; |
dns2.easydns.net [O] |
64.68.193.10 |
2620:49:2::10 |
ipv4 64.68.193.10 ok; ipv6 2620:49:2::10 ok; |
dns1.easydns.com [O] |
64.68.196.10 |
2620:49:3::10 |
ipv4 64.68.196.10 ok; ipv6 2620:49:3::10 ok; |
Mail
Dual-stack
[3 MX] v4 smtp 6/6/6 v6 smtp 4/4/4 [O]
Meaning: Shows MX footprint and SMTP health per IP family. Operational means an SMTP banner and EHLO exchange succeeded on port 25.
IPv4 SMTP 6/6/6 · IPv6 4/4/4 · location O
| Host | IPv4 | IPv6 | Probes |
sma-gov-jm.mail.protection.outlook.com [O] |
52.101.10.16, 52.101.9.26, 52.101.40.5, 52.101.9.24 |
2a01:111:f403:c902::2, 2a01:111:f403:c946::4, 2a01:111:f403:f90d::, 2a01:111:f403:c902::6 |
ipv4 52.101.10.16 ok; ipv4 52.101.9.26 ok; ipv4 52.101.40.5 ok; ipv4 52.101.9.24 ok; ipv6 2a01:111:f403:c902::2 ok; ipv6 2a01:111:f403:c946::4 ok; ipv6 2a01:111:f403:f90d:: ok; ipv6 2a01:111:f403:c902::6 ok; |
sma-gov-jm-1.fortimailcloud.com [O] |
148.230.56.131 |
— |
ipv4 148.230.56.131 ok; |
sma-gov-jm-2.fortimailcloud.com [O] |
159.48.178.132 |
— |
ipv4 159.48.178.132 ok; |
📌 Action item(s):
- Publish AAAA records for mail (MX): sma-gov-jm-1.fortimailcloud.com, sma-gov-jm-2.fortimailcloud.com.
Web
IPv4-only
[1] 0/0/0 [I]
Meaning: Shows IPv6 web endpoint readiness for the discovered HTTPS host. Operational means family-specific HTTPS requests complete successfully.
IPv4 1/1/1 · IPv6 0/0/0 · location I
| Host | IPv4 | IPv6 | Probes |
sma.gov.jm [I] |
23.235.194.197 |
— |
ipv4 ok; |
📌 Action item(s):
- Publish AAAA records for web host: sma.gov.jm.
DNSSEC
Unsigned
U/-/-
Meaning: Shows whether DNSKEY data is observed at the apex (signed), absent (unsigned), or unavailable due to lookup error.
Apex DNSKEY presence only — not full chain validation.
Analyze on DNSViz
📌 Action item(s):
- Enable DNSSEC signing and publish a DNSKEY at the apex. Use DNSViz to validate the full chain.
DMARC
p=quarantine
p=quarantine — published organizational policy. Ask receivers to quarantine failing mail; reject is stronger.
Meaning: Published DMARC policy at _dmarc.sma.gov.jm (DNS TXT). Shows organizational policy (p=) and subdomain policy (sp=) when set.
Record at _dmarc.sma.gov.jm:
v=DMARC1; p=quarantine; pct=100; rua=mailto:re+mesgfq9fnjl@dmarc.postmarkapp.com; sp=quarantine; aspf=r;
Policy publication only — SPF/DKIM not measured. Not part of the 0–4 row score.
Check on dmarcian
📌 Action item(s):
- Tighten DMARC toward p=reject when ready. Review on dmarcian.