salesforce.com
Live email deliverability and anti-spoofing audit. Every value below was read from public DNS at the moment this page was generated.
91/100 — This domain is configured correctly for both sending and receiving. Accepts mail · Protected against spoofing · Hosted by Proofpoint
Findings
-
spf
SPF ends in ~all (softfail); unauthorised mail is marked rather than rejected.
v=spf1 include:_spf.google.com include:_spf.salesforce.com exists:%{i}._spf.corp.salesforce.com ~allFix: Move to -all once you have confirmed all senders are listed.
-
mta sts
No MTA-STS policy, so inbound mail can be downgraded to an unencrypted connection.
Fix: Publish _mta-sts.salesforce.com and host a policy at https://mta-sts.salesforce.com/.well-known/mta-sts.txt.
-
mx
Mail is handled by Proofpoint.
10 mxa-00177002.gslb.pphosted.com, 10 mxb-00177002.gslb.pphosted.com
-
dmarc
DMARC is enforcing with p=reject.
v=DMARC1;p=reject;fo=1:d:s;pct=100;rua=mailto:dmarc_agg@vali.email,mailto:0e5a5c34@inbox.ondmarc.com;ruf=mailto:0e5a5c34@inbox.ondmarc.com
-
dkim
DKIM keys found for 4 selectors.
google._domainkey, s1._domainkey, s2._domainkey, mandrill._domainkey
-
bimi
BIMI is published; supporting clients can show your logo.
v=BIMI1; l=https://www.salesforce.com/content/dam/web/en_us/www/images/home/bimi-salesforce-logo.svg;
-
dnssec
DNSSEC is validating, so these records cannot be silently tampered with in transit.
AD flag set
Records
| MX | 10 mxa-00177002.gslb.pphosted.com10 mxb-00177002.gslb.pphosted.com |
|---|---|
| SPF | v=spf1 include:_spf.google.com include:_spf.salesforce.com exists:%{i}._spf.corp.salesforce.com ~all |
| DMARC | v=DMARC1;p=reject;fo=1:d:s;pct=100;rua=mailto:dmarc_agg@vali.email,mailto:0e5a5c34@inbox.ondmarc.com;ruf=mailto:0e5a5c34@inbox.ondmarc.com |
| DKIM selectors | google, s1, s2, mandrill |
| MTA-STS | not published |
| TLS-RPT | not published |
| BIMI | published |
| DNSSEC | validating |
Same data, as JSON, in one request. No SMTP probing, no stored recipient data, 250 free calls a month.
curl "https://mailgrade.dev/v1/domain?domain=salesforce.com"
Also available: /v1/verify?email=… for individual addresses, and
/v1/verify/batch for lists.