usa.gov
Live email deliverability and anti-spoofing audit, read from public DNS. Generated 2026-07-29 06:39 UTC — this page is cached for up to 6 hours, so re-check after changing a record.
60/100 — Workable, but mail from this domain is more likely to land in spam than it needs to be. Does not accept mail · Protected against spoofing
Findings
-
mx
No MX records. Mail sent to this domain has no defined destination.
Fix: Publish MX records pointing at your mail host.
-
spf
SPF ends in ~all (softfail); unauthorised mail is marked rather than rejected.
v=spf1 include:amazonses.com include:532040.spf10.hubspotemail.net ~all
Fix: Move to -all once you have confirmed all senders are listed.
-
dmarc
DMARC is enforcing with p=reject.
v=DMARC1; p=reject; pct=100; fo=1; ri=86400; rua=mailto:dmarcreports@gsa.gov,mailto:reports@dmarc.cyber.dhs.gov; ruf=mailto:dmarcfailures@gsa.gov
-
dkim
DKIM keys found for 1 selector.
hs1._domainkey
-
dnssec
DNSSEC is validating, so these records cannot be silently tampered with in transit.
AD flag set
Records
| MX | none |
|---|---|
| SPF | v=spf1 include:amazonses.com include:532040.spf10.hubspotemail.net ~all |
| DMARC | v=DMARC1; p=reject; pct=100; fo=1; ri=86400; rua=mailto:dmarcreports@gsa.gov,mailto:reports@dmarc.cyber.dhs.gov; ruf=mailto:dmarcfailures@gsa.gov |
| DKIM selectors | hs1 |
| MTA-STS | not published |
| TLS-RPT | not published |
| BIMI | not published |
| DNSSEC | validating |
Badge for your README
Live, re-checked every time someone loads the page. Free, no key required.

Swap /badge/ for /badge/dmarc/, /badge/spf/,
/badge/dkim/ or /badge/spoofable/ for a specific check.
Add ?style=plastic if you prefer the gradient.
Same data, as JSON, in one request. No SMTP probing, no stored recipient data, 250 free calls a month.
curl "https://mailgrade.dev/v1/domain?domain=usa.gov"
Also available: /v1/verify?email=… for individual addresses, and
/v1/verify/batch for lists.