Running your DNS diagnostic…
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Checking SPF, DMARC, DKIM, MX, DNS, blacklists and domain & SSL expiry. A domain we haven't scanned before takes a few seconds — hang tight.
Scanned Jul 21, 2026 13:23 UTC · 7 checks · public report
Solid base — one policy step remains.
klaviyo.com publishes an enforcing DMARC policy, so mail that forges its domain is quarantined or rejected at the recipient.
Your SPF setup is currently using a soft fail at the end, which tells receiving mail servers to treat unauthorized senders as suspicious but not automatically reject them. That matters because it gives phishers and spoofed messages a little more room to slip through. Once you’re sure every legitimate sender is included, the fix is to change the policy to a hard fail so unauthorised mail is rejected.
v=spf1 include:mg-spf.greenhouse.io include:_spf.google.com include:mail.zendesk.com include:emailus.freshservice.com include:_spf.salesforce.com ip4:4.7.16.128/26 ip4:38.108.186.0/24 ~allEdit your SPF record at Amazon Route 53 — step-by-step guide.
One send: the full report — every finding and fix — lands in your inbox, with a free account waiting. Opening it signs you in and starts a 14-day Monitor trial. No card, and you can unsubscribe in one click.
Domain owner? Re-scan any time — or email [email protected] to have this page removed.