Measurement estimates from a single vantage point — not a compliance certification. Guidance below is for operators, not an SLA.
DNS
Dual-stack
[2] 6/6/6 [O]
Meaning: Shows how many authoritative name servers exist, and how many IPv6 endpoints are configured, responsive, and operational.
IPv4 6/6/6 · IPv6 6/6/6 · location O
| Host | IPv4 | IPv6 | Probes |
lisa.ns.cloudflare.com [O] |
108.162.192.131, 172.64.32.131, 173.245.58.131 |
2a06:98c1:50::ac40:2083, 2803:f800:50::6ca2:c083, 2606:4700:50::adf5:3a83 |
ipv4 108.162.192.131 ok; ipv4 172.64.32.131 ok; ipv4 173.245.58.131 ok; ipv6 2a06:98c1:50::ac40:2083 ok; ipv6 2803:f800:50::6ca2:c083 ok; ipv6 2606:4700:50::adf5:3a83 ok; |
drew.ns.cloudflare.com [O] |
108.162.193.160, 173.245.59.160, 172.64.33.160 |
2a06:98c1:50::ac40:21a0, 2803:f800:50::6ca2:c1a0, 2606:4700:58::adf5:3ba0 |
ipv4 108.162.193.160 ok; ipv4 173.245.59.160 ok; ipv4 172.64.33.160 ok; ipv6 2a06:98c1:50::ac40:21a0 ok; ipv6 2803:f800:50::6ca2:c1a0 ok; ipv6 2606:4700:58::adf5:3ba0 ok; |
Mail
IPv4-only
[2 MX] v4 smtp 2/2/2 v6 smtp 0/0/0 [O]
Meaning: Shows MX footprint and SMTP health per IP family. Operational means an SMTP banner and EHLO exchange succeeded on port 25.
IPv4 SMTP 2/2/2 · IPv6 0/0/0 · location O
| Host | IPv4 | IPv6 | Probes |
cust62323-2.in.mailcontrol.com [O] |
116.50.58.190 |
— |
ipv4 116.50.58.190 ok; |
cust62323-1.in.mailcontrol.com [O] |
116.50.60.190 |
— |
ipv4 116.50.60.190 ok; |
📌 Action item(s):
- Publish AAAA records for mail (MX): cust62323-1.in.mailcontrol.com, cust62323-2.in.mailcontrol.com.
Web
IPv4-only
[1] 0/0/0 [I]
Meaning: Shows IPv6 web endpoint readiness for the discovered HTTPS host. Operational means family-specific HTTPS requests complete successfully.
IPv4 1/1/1 · IPv6 0/0/0 · location I
| Host | IPv4 | IPv6 | Probes |
immigration.gov.fj [I] |
172.105.184.129 |
— |
ipv4 ok; |
📌 Action item(s):
- Publish AAAA records for web host: immigration.gov.fj.
DNSSEC
Unsigned
U/-/-
Meaning: Shows whether DNSKEY data is observed at the apex (signed), absent (unsigned), or unavailable due to lookup error.
Apex DNSKEY presence only — not full chain validation.
Analyze on DNSViz
📌 Action item(s):
- Enable DNSSEC signing and publish a DNSKEY at the apex. Use DNSViz to validate the full chain.
DMARC
p=reject
p=reject — published organizational policy. Strongest published policy (SPF/DKIM alignment still not measured here).
Meaning: Published DMARC policy at _dmarc.immigration.gov.fj (DNS TXT). Shows organizational policy (p=) and subdomain policy (sp=) when set.
Record at _dmarc.immigration.gov.fj:
v=DMARC1; p=reject; pct=100
Policy publication only — SPF/DKIM not measured. Not part of the 0–4 row score.
Check on dmarcian