Public email posture · checked 2026-09-19

apple.com: DMARC, SPF and MX report

What public DNS says about how apple.com authenticates and routes email — read the way a receiving mail server reads it, with every change recorded since 2026-09-18.

grade B · enforcing DMARCTranco rank 101 snapshot
Observed configurationPublic DNS only. Nothing here required access to apple.com.
DMARCp=quarantine
SPF~all
SPF lookups2/10
MX6
DKIM selectors2
MTA-STSno
RecordValue
MX10 mx-in.g.apple.com · 20 mx-in-hfd.apple.com · 20 mx-in-ma.apple.com · 20 mx-in-rn.apple.com · 20 mx-in-sg.apple.com · 20 mx-in-vib.apple.com
SPFv=spf1 include:_spf.apple.com include:_spf-txn.apple.com ~all
DMARCv=DMARC1; p=quarantine; sp=reject; rua=mailto:d@rua.agari.com; ruf=mailto:d@ruf.agari.com;
DKIM selectorsselector1, selector2
MTA-STS / TLS-RPT / BIMIno / no / yes
Providersinbound: Self-hosted or other
Nameserversa.ns.apple.com, b.ns.apple.com, c.ns.apple.com, d.ns.apple.com
Run a live DMARC checkBuild the digital twinLive tools re-query DNS now; this report is the 2026-09-19 snapshot.

What this configuration means

Each section below is shown because the observed records match its condition. The explanations are reviewed text selected by the data, not generated from it.

DMARC requests quarantine

apple.com asks receivers to quarantine mail that fails alignment. Unaligned mail is routed to spam rather than refused, which limits the damage from spoofing while leaving a margin for misconfigured legitimate senders. The usual next step is p=reject after confirming through aggregate reports that no legitimate source still fails.

Subdomains carry a different policy

The record sets sp=reject while the organizational policy is p=quarantine. Subdomains of apple.com are therefore treated differently from the apex — a stricter policy that requires every sending subdomain to have its own aligned path.

SPF ends in soft fail

Unlisted sources produce softfail: receivers are asked to accept but mark the message. Under DMARC a softfail counts as an SPF failure, so the practical protection comes from DMARC policy rather than from ~all itself. Moving to -all is appropriate once the sender inventory is confirmed complete.

DKIM selectors are published

2 selectors resolve under _domainkey.apple.com: selector1, selector2. Selector names often identify the sending platform, and each represents a signing key that can produce an aligned DKIM path for DMARC — the path that survives forwarding.

No transport-security policy

apple.com does not publish MTA-STS, so senders negotiate TLS opportunistically and fall back to clear text if an attacker strips the upgrade. Publishing TLS-RPT first, then MTA-STS in testing mode, adds transport protection for inbound mail without risk to delivery.

BIMI record present

A BIMI record is published at default._bimi.apple.com. Logo display additionally requires an enforcing DMARC policy — which this domain has and, at most providers, a verified mark certificate.

Change history

No change has been observed since the first snapshot on 2026-09-18. The domain is re-checked regularly and a new entry appears here when any record above changes.

How to read this report

The grade summarizes two records only: A means an enforcing DMARC policy with SPF hard fail; B enforcing DMARC with SPF; C monitoring-only DMARC or a weak SPF qualifier; D one of SPF or DMARC missing; F neither published. It is a prioritization aid for the public control plane, not a statement about deliverability, reputation or the security of the organization behind the domain.

DMARC policy is discovered with the RFC 9989 DNS tree walk, so a subdomain with no record of its own is reported with the organizational policy it inherits. DKIM selectors are discovered from common names only; a domain may sign with selectors this check does not try. Everything on this page comes from public DNS as observed on 2026-09-19; caches and split-horizon DNS can show different values elsewhere.

If you operate apple.com and want a record corrected or the report removed, contact Mailybox.