Nothing here needs you.
19 DNS lookups24 blocklists askedno entriesno score, ever
read from DNS, quoted verbatim
- SPF
- -all
- DMARC
- p=reject
- DKIM
- inconclusive
- BIMI
- published
- MX
- receiving
- LISTS
- 24 asked
4 Aug 2026 · no score, no grade, nothing inferred
Who this domain authorises
Your sender list is held by Cisco Secure Email
include:iphmx.com
The record is built from SPF macros, so the senders are resolved per message at delivery time and are genuinely not readable from DNS — not by us, and not by any other checker that tells you it expanded your SPF. Whoever administers Cisco Secure Email holds the answer to which platforms may send as you; this page can only report what your own record says.
This is what your DNS authorises, not proof of what you send. A domain can authorise a platform it stopped paying for two years ago. Only a real message names the address that actually sent your campaign.
Whose job each one is
- 2fine
- 3context
Looks fine
present, ending -all
Hard fail. The strictest setting and the right one once you are confident every sender is listed.
v=spf1 include:tpo.chase.com exists:%{i}.spf.chase.com exists:%{i}.spf.hc4673-96.iphmx.com exists:%{i}.spf.hc4698-8.iphmx.com -allLooks fine
present with p=reject
A policy that actually instructs receivers, which is more than most senders publish.
v=DMARC1; p=reject; pct=100; rua=mailto:d@rua.agari.com; ruf=mailto:d@ruf.agari.com;
From DMARC p=none is monitoring, not enforcementSee what this looks like →
Context
No key found on the selectors we know
This is inconclusive, not a failure. selectors cannot be listed from , so we probed the common ones for Klaviyo, Google, Microsoft, Mailchimp, SendGrid and Postmark. A custom selector will not show up here.
From DKIM passing is not DKIM alignedSee what this looks like →
Context
record published
Your logo can appear in supporting clients, which needs at quarantine or reject.
Context
MX records present
Where you receive mail says nothing about where you send it. Marketing sends usually leave through a different platform entirely.
cluster14.us.messagelabs.com, cluster14a.us.messagelabs.com, cluster14.us.messagelabs.com
Blocklists
Nothing has an entry for you.
24 lists asked0 with an entry
chase.com is not on any of the 24 lists that answered us today. That is the whole result — there is no score, and a clean answer is allowed to be short.
Which lists, and which would not answer
- SpamCopanswered
- PSBLanswered
- Mailspikeanswered
- Spam Eating Monkeyanswered
- blocklist.deanswered
- 0SPAManswered
- InterServeranswered
- SPFBLanswered
- GBUdb Truncateanswered
- s5h.netanswered
- ZapBLanswered
- SWINOGanswered
- Kemptanswered
- Anonmailsanswered
- Fabelanswered
- NoSolicitadoanswered
- Schulteanswered
- JIPPGanswered
- UCEPROTECT Level 1answered
- UCEPROTECT Level 2answered
- UCEPROTECT Level 3answered
- Backscattereranswered
- SEM Backscatteranswered
- URIBLanswered
Each of these answered an entry it is required to publish, and one it is required not to, before we believed anything it said about you. A list that fails either is reported as unanswered rather than as clean — because a blocklist that declines to reply looks exactly like one giving you the all-clear. How we choose them.
Putting this in a client report? Embed a live, dated badge that re-checks itself.
Watch this domain
One email if authentication DNS for chase.com actually changes. Same list as rule alerts — one inbox, one promise.