Skip to content
emailrules.today
Live · nike.com3 Oct 2026

Nothing here is yours.

One finding is shared with your sending platform. The mechanical half is done and the judgement is still yours.

19 DNS lookups23 blocklists askedno entriesno score, ever

read from DNS, quoted verbatim

SPF
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
~all
DMARC
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com
p=reject
DKIM
mandrill._domainkey (Mandrill) s1._domainkey (SendGrid) s2._domainkey (SendGrid)
3 selectors
BIMI
not published
optional
MX
mxb-001b6002.gslb.pphosted.com mxa-001b6002.gslb.pphosted.com
receiving
LISTS
none of 23 blocklists hold an entry
23 asked

Who sends as you

Signs your mailSendGrid, Mandrills1._domainkey s2._domainkey mandrill._domainkey
in agreement
SPF authorisesnobody

3 Oct 2026 · no score, no grade, nothing inferred

Who this domain authorises

Your sender list is held by Proofpoint

include:%{ir}.%{v}.%{d}.spf.has.pphosted.com

The record is built from SPF macros, so the senders are resolved per message at delivery time and are genuinely not readable from DNS — not by us, and not by any other checker that tells you it expanded your SPF. Whoever administers Proofpoint holds the answer to which platforms may send as you; this page can only report what your own record says.

  • SendGrid signs your mail — and your SPF does not list it

    • s1._domainkeyDKIM key present
    • s2._domainkeyDKIM key present

    2 of SendGrid’s own selectors carry live keys, which is a setup somebody completed — not a selector collision. Your SPF names somebody else, so this mail passes DMARC on DKIM alignment alone.

Keys are also published on selectors belonging to Mandrill, and your SPF does not authorise it. Selectors like mandrill._domainkey are short enough to collide, so this is worth checking and is not worth believing on its own.

This is what your DNS authorises, not proof of what you send. A domain can authorise a platform it stopped paying for two years ago, and it can carry live keys for a platform it never authorised, which is the reverse and the more expensive of the two. Only a real message names the address that actually sent your campaign.

What this cannot see. DNS tells us what you have published, not what you actually send. It cannot read your consent records, your subject lines, or whether DKIM aligns on a real message — the three things that decide where a campaign lands. For those, send us a real campaign and we read them off the message itself.

Whose job each one is

Blocklists

Nothing has an entry for you.

23 lists asked0 with an entry1 could not be asked

nike.com is not on any of the 23 lists that answered us today. That is the whole result — there is no score, and a clean answer is allowed to be short.

Which lists, and which would not answer
  • SpamCopanswered
  • PSBLanswered
  • Mailspikeanswered
  • Spam Eating Monkeyanswered
  • blocklist.deanswered
  • 0SPAManswered
  • InterServeranswered
  • SPFBLdid not confirm the entry it is required to publish
  • GBUdb Truncateanswered
  • s5h.netanswered
  • ZapBLanswered
  • SWINOGanswered
  • Kemptanswered
  • Anonmailsanswered
  • Fabelanswered
  • NoSolicitadoanswered
  • Schulteanswered
  • JIPPGanswered
  • UCEPROTECT Level 1answered
  • UCEPROTECT Level 2answered
  • UCEPROTECT Level 3answered
  • Backscattereranswered
  • SEM Backscatteranswered
  • URIBLanswered

Each of these answered an entry it is required to publish, and one it is required not to, before we believed anything it said about you. A list that fails either is reported as unanswered rather than as clean — because a blocklist that declines to reply looks exactly like one giving you the all-clear. How we choose them.

We have observed this domain on 61 days. See what has moved since.

Putting this in a client report? Embed a live, dated badge that re-checks itself.

Watch this domain

One email if authentication DNS for nike.com actually changes. Same list as rule alerts — one inbox, one promise.

One email when a rule that matches your setup moves. Optional domain: one email if SPF, DKIM or DMARC actually changes in DNS. Nothing else.