Skip to content
emailrules.today

Authentication history · 60 days observed

notion.so

Observed from 4 Aug 2026 to 3 Oct 2026. Nothing published in DNS has moved in that window.

Where it stands today

Live lookup, 3 Oct 2026. The same check /check/notion.so runs.

  • 1worth a look
  • 1fine
  • 2context
  • Worth a look

    This record authorises nobody at all

    There is no include:, ip4: or mx before the all mechanism, so the record says that no host on the internet may send as this domain. That is the correct setting for a domain nobody sends from, and it means every message fails on a domain somebody does.

    v=spf1 ~all

    From Gmail enforces authentication, PTR, TLS and a 0.30 percent spam rateSee what this looks like →

    This one needs you

    Answer one question: does any campaign leave from this exact domain? If nothing does, this record is right and you are finished. If something does, send yourself one message and read the Authentication-Results header — it will say =fail, and it has been saying so since the record went up.

  • Looks fine

    present with p=quarantine

    A policy that actually instructs receivers, which is more than most senders publish.

    v=DMARC1; p=quarantine; pct=100; rua=mailto:re+1b3a27dd30bc@inbound.dmarcdigests.com;

    From DMARC p=none is monitoring, not enforcementSee what this looks like →

  • Context

    No key found on the selectors we know

    This is inconclusive, not a failure. selectors cannot be listed from , so we probed the common ones for Klaviyo, Google, Microsoft, Mailchimp, SendGrid and Postmark. A custom selector will not show up here.

    From DKIM passing is not DKIM alignedSee what this looks like →

  • Context

    record published

    Your logo can appear in supporting clients, which needs at quarantine or reject.

    See what this looks like →

What has moved

One entry per day a published record actually changed. Days we looked and found nothing different are counted, not listed.

  1. First observation — what was already published

    SPF published.

    v=spf1 ~all

    DMARC published.

    v=DMARC1; p=quarantine; pct=100; rua=mailto:re+1b3a27dd30bc@inbound.dmarcdigests.com;

    No DKIM key on the selectors we probe.

    BIMI published.

    v=BIMI1; l=https://vmc.digicert.com/ae66f82a-dd47-4f08-9fd9-fd865f1d0b30.svg; a=https://vmc.digicert.com/ae66f82a-dd47-4f08-9fd9-fd865f1d0b30.pem
Where this comes from. Public DNS, and nothing else. We read the same TXT and MX records any mail server reads before accepting a message, on the days someone looked. There is no scan, no login, no mail, and no score here — only what was published and the date we saw it. Gaps are days we did not get a clean answer from a resolver, and we would rather leave those blank than guess at them.