MailPosture
Scan result

cal.com

0Grade AScore
Share your score: X / Twitter LinkedIn

SPF

Which servers can send email as your domain.

Pass
DNS lookups
3/10
v=spf1 include:_spf.google.com include:sendgrid.net -all

DKIM

Cryptographic signature proving message integrity.

Pass
Selector
google
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAhg2VYUa3ZgOz9qveMqv7uEuuIZHeDjaoVpPnGeUqlEXVRZbdHeDTv24H43uxkuDCMxLao48TPOSf6VZZVjv+Hbl6mi58m9TfaXDMRM8Vg1oklij/cmaT4RYFRii0HR31lOELg4H79yhV8uXUWbvd1g8MyEKFdrunWfrzicjg8CfiLqZQqieeJ6a6I5c8DuxAq6xSbJ3FzREovesl4UVTko3yzyF9LWjmRI3xFYxeKEOYIzws8Sh6NL6GHQjU+5vCUfAeYmn0rV4ckkrmL32DExjmWzQVuYFGLhyl/2S/PxZqmFpXdVMZqPsteBjJB/r40o+dbHAbjznAj3nDdEp65wIDAQAB

DMARC

Policy for handling messages that fail SPF/DKIM.

Pass
Policy
quarantine
Reports
Configured
RUA
reports@rua.getmailposture.com
v=DMARC1; p=quarantine; rua=mailto:b71127b2@mxtoolbox.dmarc-report.com; ruf=mailto:b71127b2@forensics.dmarc-report.com; fo=1

MX Records

Where mail for this domain is delivered.

Pass
  • 1 aspmx.l.google.com.
  • 5 alt1.aspmx.l.google.com.
  • 5 alt2.aspmx.l.google.com.
  • 10 alt3.aspmx.l.google.com.
  • 10 alt4.aspmx.l.google.com.

Recommended fixes

Ordered by severity. Copy the record, paste it at your DNS registrar, and re-scan.

Nice -- no fixes needed. Your email security posture looks solid. 🎉

Monitor cal.com 24/7

Get instant email alerts the moment your SPF, DKIM, or DMARC records change or break -- before it costs you deliverability.

Start monitoring

What is SPF?

SPF (Sender Policy Framework) is a DNS TXT record that lists which mail servers are authorized to send email on behalf of cal.com. Receiving servers check the sending IP against this list; anything not listed can be rejected or marked as spam.

What is DKIM?

DKIM (DomainKeys Identified Mail) cryptographically signs outgoing messages from cal.com, letting receiving servers verify the message wasn't altered in transit and genuinely came from an authorized sender.

What is DMARC?

DMARC ties SPF and DKIM together for cal.com, defining what receiving servers should do when a message fails both checks -- and where to send aggregate reports so you can monitor abuse of your domain.