Skip to content
emailrules.today

Authentication history · 59 days observed

canva.com

Observed from 4 Aug 2026 to 3 Oct 2026. Nothing published in DNS has moved in that window.

Where it stands today

Live lookup, 3 Oct 2026. The same check /check/canva.com runs.

  • 2worth a look
  • 3fine
  • 1context
  • Worth a look

    Mailchimp signs your mail, and nothing you publish names it

    2 of Mailchimp's selectors carry live keys here, so Mailchimp is signing mail as you. Neither your record nor any of the subdomains bulk mail is normally sent from mentions Mailchimp. That is not automatically wrong: if Mailchimp sends with its own return-path domain, which is the default on every major platform, your SPF is never consulted on those messages and they pass on alone. What it does mean is that this channel has no SPF to fall back on — one key rotated, revoked or mis-copied and there is nothing underneath it.

    v=spf1 include:_spf1.canva.com include:_spf2.canva.com include:_spf3.canva.com include:_spf4.canva.com include:_spf5.canva.com include:_spf6.canva.com include:_spf7.canva.com include:_spf8.canva.com include:_spf9.canva.com -all
    k1._domainkey, k2._domainkey

    From Gmail enforces authentication, PTR, TLS and a 0.30 percent spam rateSee what this looks like →

    Part platform, part you

    Send one campaign through Mailchimp to yourself and read the Authentication-Results header. If it says =pass, the envelope is on Mailchimp's domain and there is nothing to do. If it says spf=fail or softfail, you are sending with your own domain as the envelope and Mailchimp's include: belongs in your SPF.

  • Worth a look

    SendGrid signs your mail, and nothing you publish names it

    2 of SendGrid's selectors carry live keys here, so SendGrid is signing mail as you. Neither your record nor any of the subdomains bulk mail is normally sent from mentions SendGrid. That is not automatically wrong: if SendGrid sends with its own return-path domain, which is the default on every major platform, your SPF is never consulted on those messages and they pass on alone. What it does mean is that this channel has no SPF to fall back on — one key rotated, revoked or mis-copied and there is nothing underneath it.

    v=spf1 include:_spf1.canva.com include:_spf2.canva.com include:_spf3.canva.com include:_spf4.canva.com include:_spf5.canva.com include:_spf6.canva.com include:_spf7.canva.com include:_spf8.canva.com include:_spf9.canva.com -all
    s1._domainkey, s2._domainkey

    From Gmail enforces authentication, PTR, TLS and a 0.30 percent spam rateSee what this looks like →

    Part platform, part you

    Send one campaign through SendGrid to yourself and read the Authentication-Results header. If it says =pass, the envelope is on SendGrid's domain and there is nothing to do. If it says spf=fail or softfail, you are sending with your own domain as the envelope and SendGrid's include: belongs in your SPF.

  • Looks fine

    present, ending -all

    Hard fail. The strictest setting and the right one once you are confident every sender is listed.

    v=spf1 include:_spf1.canva.com include:_spf2.canva.com include:_spf3.canva.com include:_spf4.canva.com include:_spf5.canva.com include:_spf6.canva.com include:_spf7.canva.com include:_spf8.canva.com include:_spf9.canva.com -all

    See what this looks like →

  • Looks fine

    present with p=reject

    A policy that actually instructs receivers, which is more than most senders publish.

    v=DMARC1; p=reject; rua=mailto:dmarc-reports@canva.com; ruf=mailto:dmarc-reports+forensics@canva.com; fo=1

    From DMARC p=none is monitoring, not enforcementSee what this looks like →

  • Looks fine

    keys published on 6 selectors

    A key existing is not the same as working. Read a real received header and check the d= value matches your before you call this done.

    google._domainkey (Google Workspace), k1._domainkey (Mailchimp), mandrill._domainkey (Mandrill), k2._domainkey (Mailchimp), s1._domainkey (SendGrid), s2._domainkey (SendGrid)

    From DKIM passing is not DKIM alignedSee what this looks like →

    Part platform, part you

    The key is your platform's to publish and it has. Whether it signs the domain in your is yours to confirm, and cannot show it — send one campaign to yourself and look for =pass header.d=canva.com in the Authentication-Results header.

  • Context

    Receiving mail via Google Workspace

    Where you receive mail says nothing about where you send it. Marketing sends usually leave through a different platform entirely.

    aspmx.l.google.com, alt3.aspmx.l.google.com, alt4.aspmx.l.google.com

    See what this looks like →

What has moved

One entry per day a published record actually changed. Days we looked and found nothing different are counted, not listed.

  1. First observation — what was already published

    SPF published.

    v=spf1 include:_spf1.canva.com include:_spf2.canva.com include:_spf3.canva.com include:_spf4.canva.com include:_spf5.canva.com include:_spf6.canva.com include:_spf7.canva.com include:_spf8.canva.com include:_spf9.canva.com -all

    DMARC published.

    v=DMARC1; p=reject; rua=mailto:dmarc-reports@canva.com; ruf=mailto:dmarc-reports+forensics@canva.com; fo=1

    DKIM keys on selectors we probe.

    google._domainkey (Google Workspace), k1._domainkey (Mailchimp), k2._domainkey (Mailchimp), mandrill._domainkey (Mandrill), s1._domainkey (SendGrid), s2._domainkey (SendGrid)

    MX records present.

    alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com, alt4.aspmx.l.google.com, aspmx.l.google.com
Where this comes from. Public DNS, and nothing else. We read the same TXT and MX records any mail server reads before accepting a message, on the days someone looked. There is no scan, no login, no mail, and no score here — only what was published and the date we saw it. Gaps are days we did not get a clean answer from a resolver, and we would rather leave those blank than guess at them.