customer.io
Live email deliverability and anti-spoofing audit. Every value below was read from public DNS at the moment this page was generated.
91/100 — This domain is configured correctly for both sending and receiving. Accepts mail · Protected against spoofing · Hosted by Google Workspace
Findings
-
spf
SPF ends in ~all (softfail); unauthorised mail is marked rather than rejected.
v=spf1 include:helpscoutemail.com include:_spf.google.com include:servers.mcsv.net include:amazonses.com include:mail.zendesk.com ~all
Fix: Move to -all once you have confirmed all senders are listed.
-
mta sts
No MTA-STS policy, so inbound mail can be downgraded to an unencrypted connection.
Fix: Publish _mta-sts.customer.io and host a policy at https://mta-sts.customer.io/.well-known/mta-sts.txt.
-
mx
Mail is handled by Google Workspace.
1 aspmx.l.google.com, 5 alt1.aspmx.l.google.com, 5 alt2.aspmx.l.google.com, 10 aspmx2.googlemail.com, 10 aspmx3.googlemail.com
-
dmarc
DMARC is enforcing with p=quarantine.
v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:re+a0b40970b63a@inbound.dmarcdigests.com,mailto:dmarc@rp.laneful.net; aspf=r; pct=100
-
dkim
DKIM keys found for 5 selectors.
google._domainkey, k1._domainkey, s1._domainkey, s2._domainkey, mandrill._domainkey
Records
| MX | 1 aspmx.l.google.com5 alt1.aspmx.l.google.com5 alt2.aspmx.l.google.com10 aspmx2.googlemail.com10 aspmx3.googlemail.com |
|---|---|
| SPF | v=spf1 include:helpscoutemail.com include:_spf.google.com include:servers.mcsv.net include:amazonses.com include:mail.zendesk.com ~all |
| DMARC | v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:re+a0b40970b63a@inbound.dmarcdigests.com,mailto:dmarc@rp.laneful.net; aspf=r; pct=100 |
| DKIM selectors | google, k1, s1, s2, mandrill |
| MTA-STS | not published |
| TLS-RPT | not published |
| BIMI | not published |
| DNSSEC | not validating |
Same data, as JSON, in one request. No SMTP probing, no stored recipient data, 250 free calls a month.
curl "https://mailgrade.dev/v1/domain?domain=customer.io"
Also available: /v1/verify?email=… for individual addresses, and
/v1/verify/batch for lists.