Skip to content
emailrules.today
Live · deliveroo.co.uk3 Oct 2026

Nothing here is yours.

One finding is shared with Mailchimp. The mechanical half is done and the judgement is still yours.

19 DNS lookups22 blocklists asked1 with an entryno score, ever

read from DNS, quoted verbatim

SPF
v=spf1 include:_netblocks.google.com include:_netblocks2.google.com include:_netblocks3.google.com include:_spf.salesforce.com include:mail.zendesk.com include:mailsenders.netsuite.com include:servers.mcsv.net include:spf.mandrillapp.com ip4:23.227.32.0/19 ip4:35.184.170.228 ip4:35.190.163.94 ip4:35.203.3.51 ip4:35.203.94.235 ip4:35.224.21.218 ip4:35.231.245.77 ~all
~all
DMARC
v=DMARC1; p=reject; pct=100; fo=1; ri=3600; rua=mailto:db3b2d31@inbox.ondmarc.com; ruf=mailto:db3b2d31@inbox.ondmarc.com;
p=reject
DKIM
google._domainkey (Google Workspace) k1._domainkey (Mailchimp) mandrill._domainkey (Mandrill)
3 selectors
BIMI
v=BIMI1;l=https://vmc.digicert.com/ea6c74b6-4bdb-4a2a-b252-4fa97a55850f.svg;a=https://vmc.digicert.com/ea6c74b6-4bdb-4a2a-b252-4fa97a55850f.pem
published
MX
alt1.aspmx.l.google.com alt2.aspmx.l.google.com aspmx.l.google.com aspmx2.googlemail.com aspmx3.googlemail.com
Google Workspace
LISTS
1 of 22 blocklists hold an entry
22 asked

Who sends as you

Signs your mailMailchimp, Mandrillk1._domainkey mandrill._domainkey
in agreement
SPF authorisesMailchimp, Mandrill, Zendeskinclude:servers.mcsv.net include:spf.mandrillapp.com include:mail.zendesk.com

3 Oct 2026 · no score, no grade, nothing inferred

Who this domain authorises

  • You send through Mailchimp

    • include:servers.mcsv.netread from your SPF, verbatim
    • k1._domainkeyDKIM key present
  • You send through Mandrill

    • include:spf.mandrillapp.comread from your SPF, verbatim
    • mandrill._domainkeyDKIM key present
  • Your SPF authorises Zendesk

    • include:mail.zendesk.comread from your SPF, verbatim

include:_spf.salesforce.com · google._domainkey is Salesforce and Google Workspace, which is where staff read mail. It says nothing about where campaigns leave from, and a checker that counts it as your sending platform has told you about your inbox, not your list.

This is what your DNS authorises, not proof of what you send. A domain can authorise a platform it stopped paying for two years ago, which is why an include on its own is reported as permission rather than as use. Only a real message names the address that actually sent your campaign.

What this cannot see. DNS tells us what you have published, not what you actually send. It cannot read your consent records, your subject lines, or whether DKIM aligns on a real message — the three things that decide where a campaign lands. For those, send us a real campaign and we read them off the message itself.

Whose job each one is

Blocklists

Nothing here needs you. 2 entries look alarming and are not about you.

22 lists asked1 with an entry2 could not be asked

Ignore this

  • UCEPROTECT Level 2has 35.184.170.228

    Whole address ranges, listed when UCEPROTECT sees repeated Level 1 entries inside them. Your address can appear here having done nothing.

    Who can remove it →127.0.0.2

  • UCEPROTECT Level 2has 35.190.163.94

    Whole address ranges, listed when UCEPROTECT sees repeated Level 1 entries inside them. Your address can appear here having done nothing.

    Who can remove it →127.0.0.2

Every other checker we know of shows the entries above in the same red as the ones that matter. That is how a marketer ends up paying somebody to remove a listing that was never about them.

Which lists, and which would not answer
  • SpamCopanswered
  • PSBLanswered
  • Mailspikeanswered
  • Spam Eating Monkeyanswered
  • blocklist.deanswered
  • 0SPAManswered
  • InterServeranswered
  • SPFBLdid not confirm the entry it is required to publish
  • GBUdb Truncateanswered
  • s5h.netanswered
  • ZapBLanswered
  • SWINOGanswered
  • Kemptanswered
  • Anonmailsanswered
  • Fabelanswered
  • NoSolicitadoanswered
  • Schulteanswered
  • JIPPGanswered
  • UCEPROTECT Level 1answered
  • UCEPROTECT Level 2answered
  • UCEPROTECT Level 3answered
  • Backscattereranswered
  • SEM Backscatteranswered
  • URIBLdeclined the query

Each of these answered an entry it is required to publish, and one it is required not to, before we believed anything it said about you. A list that fails either is reported as unanswered rather than as clean — because a blocklist that declines to reply looks exactly like one giving you the all-clear. How we choose them.

We have observed this domain on 61 days. See what has moved since.

Putting this in a client report? Embed a live, dated badge that re-checks itself.

Watch this domain

One email if authentication DNS for deliveroo.co.uk actually changes. Same list as rule alerts — one inbox, one promise.

One email when a rule that matches your setup moves. Optional domain: one email if SPF, DKIM or DMARC actually changes in DNS. Nothing else.