Nothing here is yours.
One finding is shared with Marketo. The mechanical half is done and the judgement is still yours.
19 DNS lookups24 blocklists askedno entriesno score, ever
read from DNS, quoted verbatim
- SPF
- ~all
- DMARC
- p=reject
- DKIM
- inconclusive
- BIMI
- published
- MX
- receiving
- LISTS
- 24 asked
Who sends as you
4 Aug 2026 · no score, no grade, nothing inferred
Who this domain authorises
Your SPF authorises Marketo
- include:mktomail.comread from your SPF, verbatim
Your SPF authorises Amazon SES
- include:amazonses.comread from your SPF, verbatim
Your SPF authorises Zendesk
- include:mail.zendesk.comread from your SPF, verbatim
include:_spf.google.com is Google Workspace, which is where staff read mail. It says nothing about where campaigns leave from, and a checker that counts it as your sending platform has told you about your inbox, not your list.
This is what your DNS authorises, not proof of what you send. A domain can authorise a platform it stopped paying for two years ago, which is why an include on its own is reported as permission rather than as use. Only a real message names the address that actually sent your campaign.
Whose job each one is
- 1worth a look
- 2fine
- 2context
Worth a look
No key, on a domain that authorises Marketo
Your authorises Marketo to send as this domain, and no key is published on any selector Marketo uses. Mail may still pass SPF, but it cannot pass , and DKIM is the half that survives forwarding.
From DKIM passing is not DKIM alignedSee what this looks like →
Part platform, part you
Open Marketo's sending-domain settings and start domain authentication. Marketo generates the key and prints the records; pasting them into is the half nobody can do for you.
Looks fine
present, ending ~all
Soft fail. Accepted everywhere, though -all is stronger once your sender list is complete.
v=spf1 ip4:45.58.64.0/20 ip4:185.45.8.0/22 ip4:162.125.0.0/16 ip4:199.47.216.0/22 ip4:108.160.160.0/20 ip4:205.189.0.0/24 ip4:160.34.15.16/28 ip4:52.5.134.202/32 ip4:205.220.162.87/32 ip4:205.220.174.83/32 ip4:167.89.98.146/32 ip4:167.89.89.46/32 ip4:167.89.96.134/32 ip4:159.183.109.97/32 ip4:149.72.220.85/32 ip4:159.183.15.144/32 ip4:159.183.2.51/32 ip4:159.183.2.58/32 ip6:2620:c6:8000::/48 include:amazonses.com include:_spf.google.com include:mail.zendesk.com include:mktomail.com include:rp.oracleemaildelivery.com exists:%{i}._spf.mta.salesforce.com ~allLooks fine
present with p=reject
A policy that actually instructs receivers, which is more than most senders publish.
v=DMARC1;p=reject;pct=100;rua=mailto:c7xrs-8253@rua.dmarc.emailanalyst.com,mailto:dmarc@dropbox.com
From DMARC p=none is monitoring, not enforcementSee what this looks like →
Context
record published
Your logo can appear in supporting clients, which needs at quarantine or reject.
Context
MX records present
Where you receive mail says nothing about where you send it. Marketing sends usually leave through a different platform entirely.
mxa-001ed902.gslb.pphosted.com, mxb-001ed902.gslb.pphosted.com
Blocklists
Nothing has an entry for you.
24 lists asked0 with an entry
dropbox.com is not on any of the 24 lists that answered us today. That is the whole result — there is no score, and a clean answer is allowed to be short.
Which lists, and which would not answer
- SpamCopanswered
- PSBLanswered
- Mailspikeanswered
- Spam Eating Monkeyanswered
- blocklist.deanswered
- 0SPAManswered
- InterServeranswered
- SPFBLanswered
- GBUdb Truncateanswered
- s5h.netanswered
- ZapBLanswered
- SWINOGanswered
- Kemptanswered
- Anonmailsanswered
- Fabelanswered
- NoSolicitadoanswered
- Schulteanswered
- JIPPGanswered
- UCEPROTECT Level 1answered
- UCEPROTECT Level 2answered
- UCEPROTECT Level 3answered
- Backscattereranswered
- SEM Backscatteranswered
- URIBLanswered
Each of these answered an entry it is required to publish, and one it is required not to, before we believed anything it said about you. A list that fails either is reported as unanswered rather than as clean — because a blocklist that declines to reply looks exactly like one giving you the all-clear. How we choose them.
Putting this in a client report? Embed a live, dated badge that re-checks itself.
Watch this domain
One email if authentication DNS for dropbox.com actually changes. Same list as rule alerts — one inbox, one promise.