Skip to content
emailrules.today

Authentication history · 2 days observed

github.com

Observed from 3 Aug 2026 to 4 Aug 2026. Nothing published in DNS has moved in that window.

Where it stands today

Live lookup, 5 Aug 2026. The same check /check/github.com runs.

  • 3fine
  • 1context
  • Looks fine

    present, ending ~all

    Soft fail. Accepted everywhere, though -all is stronger once your sender list is complete.

    v=spf1 ip4:192.30.252.0/22 include:spf.protection.outlook.com include:_netblocks.google.com include:_netblocks2.google.com include:mail.zendesk.com include:_spf.salesforce.com include:servers.mcsv.net include:mktomail.com include:sendgrid.net ip4:62.253.227.114 ip4:166.78.69.169 ip4:166.78.69.170 ip4:166.78.71.131 ~all

    See what this looks like →

  • Looks fine

    present with p=quarantine

    A policy that actually instructs receivers, which is more than most senders publish.

    v=DMARC1; p=quarantine; sp=reject; pct=100; rua=mailto:dmarc@github.com; ruf=mailto:dmarc@github.com; fo=1

    From DMARC p=none is monitoring, not enforcementSee what this looks like →

  • Looks fine

    keys published on 6 selectors

    A key existing is not the same as working. Read a real received header and check the d= value matches your before you call this done.

    google._domainkey (Google Workspace), k1._domainkey (Mailchimp), k2._domainkey (Mailchimp), selector1._domainkey (Microsoft 365), s2._domainkey (SendGrid), s1._domainkey (SendGrid)

    From DKIM passing is not DKIM alignedSee what this looks like →

    Part platform, part you

    The key is Mailchimp's to publish and it has. Whether it signs the domain in your is yours to confirm, and cannot show it — send one campaign to yourself and look for =pass header.d=github.com in the Authentication-Results header.

  • Context

    Receiving mail via Microsoft 365

    Where you receive mail says nothing about where you send it. Marketing sends usually leave through a different platform entirely.

    github-com.mail.protection.outlook.com

    See what this looks like →

What has moved

One entry per day a published record actually changed. Days we looked and found nothing different are counted, not listed.

  1. First observation — what was already published

    SPF published.

    v=spf1 ip4:192.30.252.0/22 include:spf.protection.outlook.com include:_netblocks.google.com include:_netblocks2.google.com include:mail.zendesk.com include:_spf.salesforce.com include:servers.mcsv.net include:mktomail.com include:sendgrid.net ip4:62.253.227.114 ip4:166.78.69.169 ip4:166.78.69.170 ip4:166.78.71.131 ~all

    DMARC published.

    v=DMARC1; p=quarantine; sp=reject; pct=100; rua=mailto:dmarc@github.com; ruf=mailto:dmarc@github.com; fo=1

    DKIM keys on selectors we probe.

    google._domainkey (Google Workspace), k1._domainkey (Mailchimp), k2._domainkey (Mailchimp), s1._domainkey (SendGrid), s2._domainkey (SendGrid), selector1._domainkey (Microsoft 365)

    MX records present.

    github-com.mail.protection.outlook.com
Where this comes from. Public DNS, and nothing else. We read the same TXT and MX records any mail server reads before accepting a message, on the days someone looked. There is no scan, no login, no mail, and no score here — only what was published and the date we saw it. Gaps are days we did not get a clean answer from a resolver, and we would rather leave those blank than guess at them.

FAQ

Awkward questions

Who is this actually for?

People who ship email and are too busy to re-read every PDF: week-one marketers, lifecycle/CRM, deliverability, multi-country ops, DTC brands, agencies — on Klaviyo, Mailchimp, Braze, HubSpot, SFMC, or something else. Pick your tool and geos so product-specific pages only appear when they match. EU and UK are first-class filters. Not for people who sell tools about email and need a fake score to demo.

Why only ~40 rules? Isn’t that… thin?

On purpose. A wall of 400 undated “best practices” is how you look busy and still get burned. Every page needs a primary source we actually read. Thin and checkable beats fat and folklore. Europe, bulk inbox rules, measurement honesty, and protocol topics like BIMI/DMARC policy are on the shelf when we can cite them — not every Member State and not every vendor myth. Coverage map lists what we still refuse to invent.

Is this legal advice?

No. If it were, you’d have a billable hour and a longer PDF. This is a dated operator reference written by an email geek. Confirm anything high-stakes with counsel who knows your facts. Same for “will this make me compliant?” — no tool does that. Lawyers and judges do. We say what the sources say and what to do first on Monday.

Why no trust score out of 100?

Because we refuse to invent a number you can’t audit. Fake scores sell seed tests and panic. You get findings, dates, and links. If that feels less exciting than a red dial, good — you’re not the red-dial customer.

Why should I trust you more than my ESP’s blog?

ESPs sell seats. Seed-score vendors sell fear. AI invents citations when nobody watches. We sell nothing today — no pixels, no placement scores, no affiliate — so we can say when a tool is the problem. A human verifies, dates, and corrects in public. Tools may help draft; they do not ship unsourced claims. Check the primary links. Fail that test and leave.

Do I need an account?

No. Filters live in this browser and the URL. Share the link. That’s it. Accounts come later only if they earn it — not so we can nurture you about email.

I’m an agency. Where’s multi-client mode?

We tried a client-name CRM on the setup card. It made the product feel like work before it felt useful. Role filters + copy link + one-page brief (optional PDF title) is enough for now. Complexity comes back when the free shelf is habit, not before.

Is the quiet changelog a bug?

No. Quiet means nothing material moved. We don’t invent urgency so the homepage looks “alive.” Sticky risks still show what usually needs a person when the market is still.