Apex, subdomain, or URL. We figure it out.
Results for
freshworks.com
Email authentication
The basics are in place but can be hardened.
- 2Pass
- 2Warning
- 0Fail
- 2Not set
SPF
WarningAuthorizes which servers may send mail for the domain
SPF is published but could be tightened.
- Policy
- ~all
- DNS lookups
- 8 / 10
- Ends in ~all (softfail): unauthorized senders are marked, not rejected.
- Uses 8 of 10 allowed DNS lookups. Close to the limit.
v=spf1 include:_spf.google.com include:sendgrid.net include:_spf.salesforce.com include:_spf.psm.knowbe4.com include:mktomail.com include:48900367.spf03.hubspotemail.net ip4:13.126.240.50/32 ip4:13.126.94.72/32 ip4:13.126.102.198/32 ip4:159.65.239.157 ip4:20.189.177.144/28 ip4:23.101.193.21/32 ip4:91.102.14.0/26 ip4:194.29.227.64/26 ip4:91.102.8.32/27 ip4:149.72.151.35 ip4:149.72.183.8 ip4:149.72.201.153 ip4:149.72.22.42 ip4:149.72.61.106 ip4:159.183.141.212 ip4:159.183.141.213 ip4:159.183.141.214 ip4:54.240.64.201 ip4:54.240.64.202 ip4:54.240.87.174 ip4:54.240.87.175 ip4:52.37.142.146 ip4:52.207.191.216 ~allDKIM
PassCryptographically signs outgoing mail (best-effort selector probe)
DKIM key published for 5 known selectors.
- Selectors
- google, s1, s2, mandrill, fm2
- Found a DKIM key at google._domainkey.freshworks.com
- Found a DKIM key at s1._domainkey.freshworks.com
- Found a DKIM key at s2._domainkey.freshworks.com
- Found a DKIM key at mandrill._domainkey.freshworks.com
- Found a DKIM key at fm2._domainkey.freshworks.com
DMARC
PassTells receivers what to do with mail that fails SPF and DKIM
DMARC is enforced.
- Policy
- p=quarantine
- Coverage
- 100%
- Policy p=quarantine: failing mail is sent to spam.
- Aggregate reports (rua) are configured.
v=DMARC1; p=quarantine; rua=mailto:[email protected],mailto:[email protected]; ruf=mailto:[email protected],mailto:[email protected];MTA-STS
Not setEnforces TLS for inbound mail and prevents downgrade attacks
No MTA-STS policy. Inbound mail can be delivered without TLS.
TLS-RPT
Not setReceives reports about TLS delivery failures
No TLS-RPT record. You get no reports about failed TLS delivery.
BIMI
WarningDisplays your verified brand logo in supporting inboxes
BIMI is published with caveats.
- BIMI record has no l= logo URL.
v=BIMI1;Checks query live DNS over Cloudflare and the public MTA-STS policy endpoint. DKIM selectors cannot be listed from DNS, so DKIM detection probes common provider selectors only.