mailcheckSPF · DKIM · DMARC
Know your DKIM selector?

DKIM selectors can't be listed from DNS — we guess 45 common ones. If your provider gave you a selector name we don't try, enter it here.

lyft.com

1 critical problem found

64 DNS queries in 418ms · SPF 14/10 lookups · DKIM 3 keys · DMARC p=reject · MTA-STS none · DNSSEC unsigned

Critical

SPF needs 14 DNS lookups — the limit is 10

Receivers stop evaluating at ten lookups and return a permanent error. In practice your SPF is being ignored, so mail from some of your senders is already failing authentication even though the record looks correct.

Publish this TXT record atlyft.com
v=spf1 include:qemailserver.com include:docebosaas.com include:_spf.google.com include:amazonses.com include:mail.zendesk.com include:spf_c.oraclecloud.com include:usermail.zohocreator.com include:_spf.salesforce.com ip4:23.253.182.0/23 ip4:69.72.32.0/20 ip4:87.253.232.0/21 ip4:104.130.96.0/28 ip4:104.130.122.0/23 ip4:141.193.32.0/23 ip4:143.55.224.0/21 ip4:143.55.232.0/22 ip4:143.55.236.0/22 ip4:146.20.112.0/26 ip4:146.20.113.0/24 ip4:146.20.191.0/24 ip4:159.112.240.0/20 ip4:159.135.132.128/25 ip4:159.135.140.80/29 ip4:159.135.224.0/20 ip4:161.38.192.0/20 ip4:166.78.68.0/22 ip4:185.189.236.0/22 ip4:185.211.120.0/22 ip4:185.250.236.0/22 ip4:192.237.158.0/23 ip4:198.61.254.0/23 ip4:198.244.48.0/20 ip4:204.220.160.0/21 ip4:204.220.168.0/21 ip4:204.220.176.0/20 ip4:209.61.151.0/24 -all

Before you publish: This replaces include:mailgun.org with the addresses they resolve to right now, bringing you to 9 lookups. Flattened records are a snapshot. If any of these providers changes its sending IPs, your mail from that provider starts failing SPF with no warning. Re-check monthly, or keep the include and reduce lookups another way. At 793 bytes this exceeds the 255-byte DNS character-string limit and must be published as 4 quoted strings. Most providers do this for you; some require you to enter the quotes yourself. 793 bytes is a large TXT response and may fall back to TCP on some resolvers. Prefer removing an unused sender over flattening further. 2 redundant address ranges were removed because a broader range in the same record already covers them. No sender lost coverage.

Warning

3 DKIM keys are shorter than 2048 bits

google (1024-bit), k1 (1024-bit), mandrill (1024-bit). 1024-bit RSA is still accepted everywhere but is no longer considered strong, and some receivers have begun downgrading it. Rotation is handled by your provider, not by editing DNS directly.

What to do
  1. Ask the provider behind Google Workspace, Mailchimp / Mandrill, Mandrill to reissue at 2048 bits.
  2. Publish the new key on a fresh selector, then remove the old one once mail is signing with it.
Note

No MTA-STS policy

Mail sent to you can be downgraded to an unencrypted connection by an attacker on the network. MTA-STS closes that hole. Optional, but it is what separates a well-run mail domain from an average one.

Publish this TXT record at_mta-sts.lyft.com
v=STSv1; id=20260731000000

Before you publish: The record alone does nothing — you must also serve a policy file at https://mta-sts.lyft.com/.well-known/mta-sts.txt listing your MX hosts. Start with mode: testing, and only move to enforce once reports confirm nothing is failing.

Note

No TLS reporting

TLS-RPT asks other mail providers to tell you when encrypted delivery to your domain fails. It is the feedback loop that makes MTA-STS safe to enforce — without it you are switching on enforcement blind.

Publish this TXT record at_smtp._tls.lyft.com
v=TLSRPTv1; rua=mailto:tlsrpt@lyft.com

Before you publish: The mailbox must exist. Reports arrive daily as JSON attachments.

Note

Your domain qualifies for BIMI

lyft.com enforces DMARC, which is the hard prerequisite for BIMI — displaying your logo beside your messages in supporting inboxes. Adding it is now mostly a matter of hosting an SVG, plus a Verified Mark Certificate if you want Gmail to honour it.

Note

DNSSEC is not enabled

lyft.com is unsigned, so an attacker able to tamper with DNS responses could forge your SPF, DKIM and DMARC records — undermining all three. Most registrars and DNS hosts enable it with one click.

What to do
  1. Enable DNSSEC in your DNS provider (Cloudflare: DNS → Settings → Enable DNSSEC).
  2. Copy the DS record it generates into your registrar. Some registrars do this automatically.
Good

DMARC is at p=reject

The strongest policy. Mail failing authentication is rejected outright.

Records as published

SPF · lyft.com
v=spf1 include:qemailserver.com include:docebosaas.com include:_spf.google.com include:mailgun.org include:amazonses.com include:mail.zendesk.com include:spf_c.oraclecloud.com include:usermail.zohocreator.com include:_spf.salesforce.com -all
DMARC · _dmarc.lyft.com
v=DMARC1; p=reject; pct=100; rua=mailto:6ig9o43x@ag.dmarcian.com; ruf=mailto:6ig9o43x@fr.dmarcian.com;
MX
1  aspmx.l.google.com
5  alt1.aspmx.l.google.com
5  alt2.aspmx.l.google.com
10  alt3.aspmx.l.google.com
10  alt4.aspmx.l.google.com
DKIM selectors found
  • googleGoogle Workspacersa 1024-bit
  • k1Mailchimp / Mandrillrsa 1024-bit
  • mandrillMandrillrsa 1024-bit