Two of these are yours.
19 DNS lookups23 blocklists asked1 with an entryno score, ever
read from DNS, quoted verbatim
- SPF
- -all
- DMARC
- p=reject
- DKIM
- 5 selectors
- BIMI
- optional
- MX
- Microsoft 365
- LISTS
- 23 asked
Who sends as you
4 Aug 2026 · no score, no grade, nothing inferred
Who this domain authorises
You send through Mailchimp
- include:servers.mcsv.netread from your SPF, verbatim
- k1._domainkeyDKIM key present
You send through SendGrid
- include:sendgrid.netread from your SPF, verbatim
- s1._domainkeyDKIM key present
- s2._domainkeyDKIM key present
Your SPF authorises Amazon SES
- include:amazonses.comread from your SPF, verbatim
Your SPF authorises Shopify
- include:shops.shopify.comread from your SPF, verbatim
include:spf.protection.outlook.com is Microsoft 365, which is where staff read mail. It says nothing about where campaigns leave from, and a checker that counts it as your sending platform has told you about your inbox, not your list.
This is what your DNS authorises, not proof of what you send. A domain can authorise a platform it stopped paying for two years ago, which is why an include on its own is reported as permission rather than as use. Only a real message names the address that actually sent your campaign.
Whose job each one is
- 3fine
- 1context
Looks fine
present, ending -all
Hard fail. The strictest setting and the right one once you are confident every sender is listed.
v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net include:shops.shopify.com include:sendgrid.net include:emaileuc.freshservice.com include:amazonses.com ip4:77.81.189.101 ip4:46.254.14.229 ip4:168.245.76.176 ip4:194.68.215.35 ip4:87.253.233.197 -all
Looks fine
present with p=reject
A policy that actually instructs receivers, which is more than most senders publish.
v=DMARC1; p=reject; rua=mailto:yd816iek@ag.eu.dmarcadvisor.com,mailto:rua@dmarc.portsgroup.com;
From DMARC p=none is monitoring, not enforcementSee what this looks like →
Looks fine
keys published on 5 selectors
A key existing is not the same as working. Read a real received header and check the d= value matches your before you call this done.
k1._domainkey (Mailchimp), selector2._domainkey (Microsoft 365), s2._domainkey (SendGrid), s1._domainkey (SendGrid), selector1._domainkey (Microsoft 365)
From DKIM passing is not DKIM alignedSee what this looks like →
Part platform, part you
The key is Mailchimp's to publish and it has. Whether it signs the domain in your is yours to confirm, and cannot show it — send one campaign to yourself and look for =pass header.d=oatly.com in the Authentication-Results header.
Context
Receiving mail via Microsoft 365
Where you receive mail says nothing about where you send it. Marketing sends usually leave through a different platform entirely.
oatly-com.mail.protection.outlook.com
Blocklists
2 entries need you.
23 lists asked1 with an entry1 could not be asked
Needs you
SPFBLhas 77.81.189.101
Addresses with poor reputation in SPFBL's distributed reputation system.
How to request removal →127.0.0.5
SPFBLhas 46.254.14.229
Addresses with poor reputation in SPFBL's distributed reputation system.
How to request removal →127.0.0.5
Which lists, and which would not answer
- SpamCopanswered
- PSBLanswered
- Mailspikeanswered
- Spam Eating Monkeyanswered
- blocklist.deanswered
- 0SPAManswered
- InterServeranswered
- SPFBLanswered
- GBUdb Truncateanswered
- s5h.netanswered
- ZapBLanswered
- SWINOGanswered
- Kemptanswered
- Anonmailsanswered
- Fabelanswered
- NoSolicitadoanswered
- Schulteanswered
- JIPPGanswered
- UCEPROTECT Level 1answered
- UCEPROTECT Level 2answered
- UCEPROTECT Level 3answered
- Backscattereranswered
- SEM Backscatteranswered
- URIBLdeclined the query
Each of these answered an entry it is required to publish, and one it is required not to, before we believed anything it said about you. A list that fails either is reported as unanswered rather than as clean — because a blocklist that declines to reply looks exactly like one giving you the all-clear. How we choose them.
Putting this in a client report? Embed a live, dated badge that re-checks itself.
Watch this domain
One email if authentication DNS for oatly.com actually changes. Same list as rule alerts — one inbox, one promise.