Skip to content
emailrules.today

Authentication history · 60 days observed

dropbox.com

Observed from 4 Aug 2026 to 3 Oct 2026. Nothing published in DNS has moved in that window.

Where it stands today

Live lookup, 3 Oct 2026. The same check /check/dropbox.com runs.

  • 1worth a look
  • 2fine
  • 2context
  • Worth a look

    No key, on a domain that authorises Marketo

    Your authorises Marketo to send as this domain, and no key is published on any selector Marketo uses. Mail may still pass SPF, but it cannot pass , and DKIM is the half that survives forwarding.

    From DKIM passing is not DKIM alignedSee what this looks like →

    Part platform, part you

    Open Marketo's sending-domain settings and start domain authentication. Marketo generates the key and prints the records; pasting them into is the half nobody can do for you.

  • Looks fine

    present, ending ~all

    Soft fail. Accepted everywhere, though -all is stronger once your sender list is complete.

    v=spf1 ip4:45.58.64.0/20 ip4:185.45.8.0/22 ip4:162.125.0.0/16 ip4:199.47.216.0/22 ip4:108.160.160.0/20 ip4:205.189.0.0/24 ip4:160.34.15.16/28 ip4:52.5.134.202/32 ip4:205.220.162.87/32 ip4:205.220.174.83/32 ip4:167.89.98.146/32 ip4:167.89.89.46/32 ip4:167.89.96.134/32 ip4:159.183.109.97/32 ip4:149.72.220.85/32 ip4:159.183.15.144/32 ip4:159.183.2.51/32 ip4:159.183.2.58/32 ip6:2620:c6:8000::/48 include:amazonses.com include:_spf.google.com include:mail.zendesk.com include:mktomail.com include:rp.oracleemaildelivery.com exists:%{i}._spf.mta.salesforce.com ~all

    See what this looks like →

  • Looks fine

    present with p=reject

    A policy that actually instructs receivers, which is more than most senders publish.

    v=DMARC1;p=reject;pct=100;rua=mailto:c7xrs-8253@rua.dmarc.emailanalyst.com,mailto:dmarc@dropbox.com

    From DMARC p=none is monitoring, not enforcementSee what this looks like →

  • Context

    record published

    Your logo can appear in supporting clients, which needs at quarantine or reject.

    See what this looks like →

  • Context

    MX records present

    Where you receive mail says nothing about where you send it. Marketing sends usually leave through a different platform entirely.

    mxb-001ed902.gslb.pphosted.com, mxa-001ed902.gslb.pphosted.com

    See what this looks like →

What has moved

One entry per day a published record actually changed. Days we looked and found nothing different are counted, not listed.

  1. First observation — what was already published

    SPF published.

    v=spf1 ip4:45.58.64.0/20 ip4:185.45.8.0/22 ip4:162.125.0.0/16 ip4:199.47.216.0/22 ip4:108.160.160.0/20 ip4:205.189.0.0/24 ip4:160.34.15.16/28 ip4:52.5.134.202/32 ip4:205.220.162.87/32 ip4:205.220.174.83/32 ip4:167.89.98.146/32 ip4:167.89.89.46/32 ip4:167.89.96.134/32 ip4:159.183.109.97/32 ip4:149.72.220.85/32 ip4:159.183.15.144/32 ip4:159.183.2.51/32 ip4:159.183.2.58/32 ip6:2620:c6:8000::/48 inclu…

    DMARC published.

    v=DMARC1;p=reject;pct=100;rua=mailto:c7xrs-8253@rua.dmarc.emailanalyst.com,mailto:dmarc@dropbox.com

    No DKIM key on the selectors we probe.

    BIMI published.

    v=BIMI1;l=https://cfl.dropboxstatic.com/static/metaserver/static/images/emails/bimi/order_400664024_logo.svg;a=https://cfl.dropboxstatic.com/static/metaserver/static/images/emails/bimi/dropbox_inc.pem

    MX records present.

    mxa-001ed902.gslb.pphosted.com, mxb-001ed902.gslb.pphosted.com
Where this comes from. Public DNS, and nothing else. We read the same TXT and MX records any mail server reads before accepting a message, on the days someone looked. There is no scan, no login, no mail, and no score here — only what was published and the date we saw it. Gaps are days we did not get a clean answer from a resolver, and we would rather leave those blank than guess at them.