Public email posture · checked 2026-09-23

akamaiedge.net: DMARC, SPF and MX report

What public DNS says about how akamaiedge.net authenticates and routes email — read the way a receiving mail server reads it, with every change recorded since 2026-09-22.

grade F · no SPF and no DMARCTranco rank 231 snapshot
Observed configurationPublic DNS only. Nothing here required access to akamaiedge.net.
DMARCnone
SPFnone
SPF lookups
MX2
DKIM selectors0
MTA-STSno
RecordValue
MX100 mx0a-00190b01.pphosted.com · 100 mx0b-00190b01.pphosted.com
SPF
DMARC
DKIM selectorsnone of the common names resolve
MTA-STS / TLS-RPT / BIMIno / no / no
Providersinbound: Proofpoint
Nameserversa1-192.akamaiedge.net, a11-192.akamaiedge.net, a12-192.akamaiedge.net, a13-192.akamaiedge.net, a28-192.akamaiedge.net, a6-192.akamaiedge.net
Run a live DMARC checkBuild the digital twinLive tools re-query DNS now; this report is the 2026-09-23 snapshot.

What this configuration means

Each section below is shown because the observed records match its condition. The explanations are reviewed text selected by the data, not generated from it.

No DMARC policy applies

No valid DMARC record was found for akamaiedge.net, and the RFC 9989 discovery walk found no organizational policy to inherit. Receivers therefore have no instruction for mail that fails SPF and DKIM alignment, which means the domain can be used in the From field of a spoofed message without any policy asking for rejection. Publishing even a monitoring policy (p=none) with an aggregate reporting address starts producing evidence of who sends as the domain.

No SPF record

akamaiedge.net publishes no v=spf1 record, so receivers cannot evaluate whether a connecting server is authorized to use the domain as the envelope sender. Every platform that sends for the domain should be listed; until then, SPF cannot contribute an aligned path for DMARC.

No common DKIM selectors found

None of the selector names commonly used by major platforms resolve under _domainkey.akamaiedge.net. DKIM has no enumeration mechanism, so the domain may sign with a selector this check does not try; absence here is not proof that DKIM is unused. It does mean no platform with a conventional selector is publicly visible.

No transport-security policy

akamaiedge.net does not publish MTA-STS, so senders negotiate TLS opportunistically and fall back to clear text if an attacker strips the upgrade. Publishing TLS-RPT first, then MTA-STS in testing mode, adds transport protection for inbound mail without risk to delivery.

Change history

No change has been observed since the first snapshot on 2026-09-22. The domain is re-checked regularly and a new entry appears here when any record above changes.

How to read this report

The grade summarizes two records only: A means an enforcing DMARC policy with SPF hard fail; B enforcing DMARC with SPF; C monitoring-only DMARC or a weak SPF qualifier; D one of SPF or DMARC missing; F neither published. It is a prioritization aid for the public control plane, not a statement about deliverability, reputation or the security of the organization behind the domain.

DMARC policy is discovered with the RFC 9989 DNS tree walk, so a subdomain with no record of its own is reported with the organizational policy it inherits. DKIM selectors are discovered from common names only; a domain may sign with selectors this check does not try. Everything on this page comes from public DNS as observed on 2026-09-23; caches and split-horizon DNS can show different values elsewhere.

If you operate akamaiedge.net and want a record corrected or the report removed, contact Mailybox.