Nothing here is yours.
3 findings are shared with your sending platform. The mechanical half is done and the judgement is still yours.
19 DNS lookups24 blocklists askedno entriesno score, ever
read from DNS, quoted verbatim
- SPF
- -all
- DMARC
- p=reject
- DKIM
- 6 selectors
- BIMI
- optional
- MX
- Google Workspace
- LISTS
- 24 asked
Who sends as you
4 Aug 2026 · no score, no grade, nothing inferred
Who this domain authorises
Mailchimp signs your mail — and your SPF does not list it
- k1._domainkeyDKIM key present
- k2._domainkeyDKIM key present
2 of Mailchimp’s own selectors carry live keys, which is a setup somebody completed — not a selector collision. Your SPF names somebody else, so this mail passes DMARC on DKIM alignment alone.
SendGrid signs your mail — and your SPF does not list it
- s1._domainkeyDKIM key present
- s2._domainkeyDKIM key present
2 of SendGrid’s own selectors carry live keys, which is a setup somebody completed — not a selector collision. Your SPF names somebody else, so this mail passes DMARC on DKIM alignment alone.
Keys are also published on selectors belonging to Mandrill, and your SPF does not authorise it. Selectors like mandrill._domainkey are short enough to collide, so this is worth checking and is not worth believing on its own.
google._domainkey is Google Workspace, which is where staff read mail. It says nothing about where campaigns leave from, and a checker that counts it as your sending platform has told you about your inbox, not your list.
This is what your DNS authorises, not proof of what you send. A domain can authorise a platform it stopped paying for two years ago, and it can carry live keys for a platform it never authorised, which is the reverse and the more expensive of the two. Only a real message names the address that actually sent your campaign.
Whose job each one is
- 2worth a look
- 3fine
- 1context
Worth a look
Mailchimp signs your mail, and nothing you publish names it
2 of Mailchimp's selectors carry live keys here, so Mailchimp is signing mail as you. Neither your record nor any of the subdomains bulk mail is normally sent from mentions Mailchimp. That is not automatically wrong: if Mailchimp sends with its own return-path domain, which is the default on every major platform, your SPF is never consulted on those messages and they pass on alone. What it does mean is that this channel has no SPF to fall back on — one key rotated, revoked or mis-copied and there is nothing underneath it.
v=spf1 include:_spf1.canva.com include:_spf2.canva.com include:_spf3.canva.com include:_spf4.canva.com include:_spf5.canva.com include:_spf6.canva.com include:_spf7.canva.com include:_spf8.canva.com include:_spf9.canva.com -all k1._domainkey, k2._domainkey
From Gmail enforces authentication, PTR, TLS and a 0.30 percent spam rateSee what this looks like →
Part platform, part you
Send one campaign through Mailchimp to yourself and read the Authentication-Results header. If it says =pass, the envelope is on Mailchimp's domain and there is nothing to do. If it says spf=fail or softfail, you are sending with your own domain as the envelope and Mailchimp's include: belongs in your SPF.
Worth a look
SendGrid signs your mail, and nothing you publish names it
2 of SendGrid's selectors carry live keys here, so SendGrid is signing mail as you. Neither your record nor any of the subdomains bulk mail is normally sent from mentions SendGrid. That is not automatically wrong: if SendGrid sends with its own return-path domain, which is the default on every major platform, your SPF is never consulted on those messages and they pass on alone. What it does mean is that this channel has no SPF to fall back on — one key rotated, revoked or mis-copied and there is nothing underneath it.
v=spf1 include:_spf1.canva.com include:_spf2.canva.com include:_spf3.canva.com include:_spf4.canva.com include:_spf5.canva.com include:_spf6.canva.com include:_spf7.canva.com include:_spf8.canva.com include:_spf9.canva.com -all s1._domainkey, s2._domainkey
From Gmail enforces authentication, PTR, TLS and a 0.30 percent spam rateSee what this looks like →
Part platform, part you
Send one campaign through SendGrid to yourself and read the Authentication-Results header. If it says =pass, the envelope is on SendGrid's domain and there is nothing to do. If it says spf=fail or softfail, you are sending with your own domain as the envelope and SendGrid's include: belongs in your SPF.
Looks fine
present, ending -all
Hard fail. The strictest setting and the right one once you are confident every sender is listed.
v=spf1 include:_spf1.canva.com include:_spf2.canva.com include:_spf3.canva.com include:_spf4.canva.com include:_spf5.canva.com include:_spf6.canva.com include:_spf7.canva.com include:_spf8.canva.com include:_spf9.canva.com -all
Looks fine
present with p=reject
A policy that actually instructs receivers, which is more than most senders publish.
v=DMARC1; p=reject; rua=mailto:dmarc-reports@canva.com; ruf=mailto:dmarc-reports+forensics@canva.com; fo=1
From DMARC p=none is monitoring, not enforcementSee what this looks like →
Looks fine
keys published on 6 selectors
A key existing is not the same as working. Read a real received header and check the d= value matches your before you call this done.
k1._domainkey (Mailchimp), google._domainkey (Google Workspace), mandrill._domainkey (Mandrill), k2._domainkey (Mailchimp), s1._domainkey (SendGrid), s2._domainkey (SendGrid)
From DKIM passing is not DKIM alignedSee what this looks like →
Part platform, part you
The key is your platform's to publish and it has. Whether it signs the domain in your is yours to confirm, and cannot show it — send one campaign to yourself and look for =pass header.d=canva.com in the Authentication-Results header.
Context
Receiving mail via Google Workspace
Where you receive mail says nothing about where you send it. Marketing sends usually leave through a different platform entirely.
alt3.aspmx.l.google.com, alt4.aspmx.l.google.com, alt1.aspmx.l.google.com
Blocklists
Nothing has an entry for you.
24 lists asked0 with an entry
canva.com is not on any of the 24 lists that answered us today. That is the whole result — there is no score, and a clean answer is allowed to be short.
Which lists, and which would not answer
- SpamCopanswered
- PSBLanswered
- Mailspikeanswered
- Spam Eating Monkeyanswered
- blocklist.deanswered
- 0SPAManswered
- InterServeranswered
- SPFBLanswered
- GBUdb Truncateanswered
- s5h.netanswered
- ZapBLanswered
- SWINOGanswered
- Kemptanswered
- Anonmailsanswered
- Fabelanswered
- NoSolicitadoanswered
- Schulteanswered
- JIPPGanswered
- UCEPROTECT Level 1answered
- UCEPROTECT Level 2answered
- UCEPROTECT Level 3answered
- Backscattereranswered
- SEM Backscatteranswered
- URIBLanswered
Each of these answered an entry it is required to publish, and one it is required not to, before we believed anything it said about you. A list that fails either is reported as unanswered rather than as clean — because a blocklist that declines to reply looks exactly like one giving you the all-clear. How we choose them.
Putting this in a client report? Embed a live, dated badge that re-checks itself.
Watch this domain
One email if authentication DNS for canva.com actually changes. Same list as rule alerts — one inbox, one promise.