github.com
Email authentication is in good shape.
Checked Tue, 01 Sep 2026 20:13:35 GMT using public DNS · 179 ms
Know before this breaks
Records drift: a new SaaS tool pushes SPF over 10 lookups, a DKIM key gets rotated, someone edits DMARC. MailAuthWatch re-checks github.com every day and alerts you by email or Slack the moment anything changes.
Monitor github.com from $29/monthSPF OK
v=spf1 ip4:192.30.252.0/22 include:spf.protection.outlook.com include:_netblocks.google.com include:_netblocks2.google.com include:mail.zendesk.com include:_spf.salesforce.com include:servers.mcsv.net include:mktomail.com include:sendgrid.net ip4:62.253.227.114 ip4:166.78.69.169 ip4:166.78.69.170 ip4:166.78.71.131 ~all
- DNS lookups
- 10 of 10 allowed
- Final mechanism
~all
- WarningSPF uses 10 of 10 allowed DNS lookups. Adding one more service may break SPF.
- NoteSPF record is 320 characters; ensure it is split into 255-byte strings at your DNS host.
Include chain (9 lookups resolved)
| Domain | Via | Status | Record |
|---|---|---|---|
spf.protection.outlook.com | root | OK | v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all |
_netblocks.google.com | root | OK | v=spf1 ip4:74.125.0.0/16 ip4:209.85.128.0/17 ~all |
_netblocks2.google.com | root | OK | v=spf1 ip6:2001:4860:4000::/36 ip6:2404:6800:4000::/36 ip6:2607:f8b0:4000::/36 ip6:2800:3f0:4000::/36 ip6:2a00:1450:4000::/36 ip6:2c0f:fb50:4000::/36 ~all |
mail.zendesk.com | root | OK | v=spf1 ip4:103.151.192.0/23 ip4:185.12.80.0/22 ip4:188.172.128.0/20 ip4:192.161.144.0/20 ip4:216.198.0.0/18 ~all |
_spf.salesforce.com | root | OK | v=spf1 exists:%{i}._spf.mta.salesforce.com -all |
servers.mcsv.net | root | OK | v=spf1 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.0.0/16 -all |
mktomail.com | root | OK | v=spf1 ip4:199.15.212.0/22 ip4:72.3.185.0/24 ip4:72.32.154.0/24 ip4:72.32.217.0/24 ip4:72.32.243.0/24 ip4:94.236.119.0/26 ip4:37.188.97.188/32 ip4:185.28.196.0/22 ip4:192.28.128.0/18 ip4:103.237.104.0/22 ip4:130.248.172.0/24 ip4:130.248.173.0/24 ~all |
sendgrid.net | root | OK | v=spf1 ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip4:159.183.0.0/16 ip4:134.128.64.0/19 ip4:134.128.96.0/19 include:ab.sendgrid.net ~all |
ab.sendgrid.net | sendgrid.net | OK | v=spf1 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23 ~all |
DKIM OK
DKIM selectors cannot be listed from DNS, so 79 selectors used by common providers were probed.
| Selector | Key | Record |
|---|---|---|
selector1 | RSA 1024-bit Weak | v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCxZC/z2cK+2s1f/ktzSDSeFzkfIHrjwtGF… |
google | RSA 2048-bit OK | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAj6T5sl/RwdSqGoYWaWaFbS2UAeyP… |
k1 | RSA 1024-bit Weak | k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i8… |
k2 | RSA 2048-bit OK | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBX… |
k3 | RSA 2048-bit OK | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsYGiMSn7fsUqSvfSX40x9R1OlRtb… |
s1 | RSA 2048-bit OK | k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyn3fMCVpb7ryIRKOGXhXVGYmsWUitNlS… |
s2 | RSA 2048-bit OK | k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnNt2/H6bKs99C6DAaokPp62KN9mKaD20… |
cm | RSA 1024-bit Weak | k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDXLybkpDQnCyQYlQc46kL2sPMsYDqwkjPyFRSDiaq6q… |
zendesk1 | RSA 2048-bit OK | v=DKIM1;t=s;n=core;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9IqdLrO3Zr2/56MHt8o… |
zendesk2 | RSA 2048-bit OK | v=DKIM1; t=s; n=core; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmiSFNkgXrO3I8aO… |
mailo | RSA 1024-bit Weak | k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQPJBpMLQPx0UvC5HXIoVHgwfowk1OjOqnQNcVjbcpK… |
smtpapi | RSA 1024-bit Weak | k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r… |
- WarningDKIM selectors "selector1", "k1", "cm", "mailo", "smtpapi" use 1024-bit keys. Rotate to 2048 bits.
DMARC OK
v=DMARC1; p=quarantine; sp=reject; pct=100; rua=mailto:dmarc@github.com; ruf=mailto:dmarc@github.com; fo=1
- Policy
p=quarantine· subdomainssp=reject- Applies to
- 100% of failing mail
- Aggregate reports
mailto:dmarc@github.com
- NotePolicy is p=quarantine. p=reject is the strongest protection once you are confident all senders are aligned.
Mail exchange and extras
| Priority | Exchange |
|---|---|
| 0 | github-com.mail.protection.outlook.com |
- OK No problems detected.
- MTA-STS
- Not published optional: enforces TLS for inbound mail
- TLS-RPT
- Not published
- BIMI
- Not published optional: brand logo in inboxes, requires p=quarantine or reject
How the grade is calculated
Score 95/100. SPF present and valid. SPF ends with ~all. DKIM found (12 selectors). DKIM key is 2048-bit or stronger. DMARC present and valid. DMARC policy is quarantine. DMARC aggregate reporting enabled. SPF contributes up to 35 points, DKIM up to 25, DMARC up to 40 (policy strength and reporting). Any critical issue caps the grade at C. Lookups that failed are shown as "not measured" and never counted as missing.
Check another domain:
Re-run without cache · Guides and tools
Other recently graded domains
Public checks run in the last few days. Every report is measured live from DNS when it is opened.