Public email posture · checked 2026-09-09

cloudflare.com: DMARC, SPF and MX report

What public DNS says about how cloudflare.com authenticates and routes email — read the way a receiving mail server reads it, with every change recorded since 2026-09-08.

grade A · enforcing DMARC with SPF hard fail1 snapshot
Observed configurationPublic DNS only. Nothing here required access to cloudflare.com.
DMARCp=reject
SPF-all
SPF lookups6/10
MX4
DKIM selectors4
MTA-STSyes
RecordValue
MX5 mxa-canary.global.inbound.cf-emailsecurity.net · 5 mxb-canary.global.inbound.cf-emailsecurity.net · 10 mxa.global.inbound.cf-emailsecurity.net · 10 mxb.global.inbound.cf-emailsecurity.net
SPFv=spf1 ip4:199.15.212.0/22 ip4:173.245.48.0/20 include:_spf.google.com include:spf1.mcsv.net include:spf.mandrillapp.com include:mail.zendesk.com include:stspg-customer.com include:_spf.salesforce.com -all
DMARCv=DMARC1; p=reject; sp=reject; adkim=r; aspf=r; pct=100; rua=mailto:a1c47f179bc04efd8ee4dcd4d85dfc65@dmarc-reports.cloudflare.net,mailto:rua@cloudflare.com
DKIM selectorss1, k1, smtpapi, mandrill
MTA-STS / TLS-RPT / BIMIyes / yes / yes
Providersinbound: Cloudflare Email Security · sending: Google Workspace, Mailchimp, Zendesk
Nameserversns3.cloudflare.com, ns4.cloudflare.com, ns5.cloudflare.com, ns6.cloudflare.com, ns7.cloudflare.com
Run a live DMARC checkBuild the digital twinLive tools re-query DNS now; this report is the 2026-09-09 snapshot.

What this configuration means

Each section below is shown because the observed records match its condition. The explanations are reviewed text selected by the data, not generated from it.

DMARC enforces rejection

cloudflare.com publishes p=reject. Receivers that honour DMARC refuse mail using this domain in From unless SPF or DKIM aligns. This is the strongest published posture; it depends on every legitimate sender — including third-party platforms — having an aligned path, and on the aggregate reports the record requests to catch regressions.

DKIM selectors are published

4 selectors resolve under _domainkey.cloudflare.com: s1, k1, smtpapi, mandrill. Selector names often identify the sending platform, and each represents a signing key that can produce an aligned DKIM path for DMARC — the path that survives forwarding.

MTA-STS is published

cloudflare.com declares a transport-security policy. The policy asks senders to make no change; it is published but not protective. TLS-RPT is also published, so transport failures are reported.

BIMI record present

A BIMI record is published at default._bimi.cloudflare.com. Logo display additionally requires an enforcing DMARC policy — which this domain has and, at most providers, a verified mark certificate.

Sending platforms visible in DNS

Public records reference 3 platforms: Google Workspace, Mailchimp, Zendesk. Each SPF include or DKIM selector is an authorization that someone must own. Platforms no longer in use remain authorized until the records are removed.

Change history

No change has been observed since the first snapshot on 2026-09-08. The domain is re-checked regularly and a new entry appears here when any record above changes.

How to read this report

The grade summarizes two records only: A means an enforcing DMARC policy with SPF hard fail; B enforcing DMARC with SPF; C monitoring-only DMARC or a weak SPF qualifier; D one of SPF or DMARC missing; F neither published. It is a prioritization aid for the public control plane, not a statement about deliverability, reputation or the security of the organization behind the domain.

DMARC policy is discovered with the RFC 9989 DNS tree walk, so a subdomain with no record of its own is reported with the organizational policy it inherits. DKIM selectors are discovered from common names only; a domain may sign with selectors this check does not try. Everything on this page comes from public DNS as observed on 2026-09-09; caches and split-horizon DNS can show different values elsewhere.

If you operate cloudflare.com and want a record corrected or the report removed, contact Mailybox.