Skip to content
emailrules.today

Authentication history · 58 days observed

npr.org

Observed from 4 Aug 2026 to 3 Oct 2026. Nothing published in DNS has moved in that window.

Where it stands today

Live lookup, 3 Oct 2026. The same check /check/npr.org runs.

  • 3fine
  • 3context
  • Looks fine

    present, ending -all

    Hard fail. The strictest setting and the right one once you are confident every sender is listed.

    v=spf1 include:spf-0032f701.pphosted.com include:spf.protection.outlook.com include:prss.org exists:%{i}._spf.mta.salesforce.com include:c9eb27a2d7.berenice.eoidentity.com ip4:64.124.132.59/32 ip4:66.150.167.192/27 ip4:162.242.229.170 ip4:205.153.38.0/24 ip4:205.153.36.170 ip4:40.107.0.0/16 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.0.0/16 ip4:139.60.0.0/24 ip4:139.60.1.0/24 ip4:139.60.2.0/24 ip4:139.60.3.0/24 ip4:13.111.0.0/16 ip4:136.147.135.0/24 ip4:136.147.176.0/24 ip4:136.147.182.0/24 ip4:198.245.81.0/24 ip4:199.122.123.0/24 ip4:195.66.99.135 ip4:212.227.89.57 ip4:217.160.226.166 ip4:54.194.192.132 ip4:62.75.247.44 ip4:82.165.193.1 ip4:85.25.144.9 ip4:87.79.30.25 ip4:87.79.30.30 ip4:208.86.168.7 ip4:135.84.68.123 ip4:206.152.14.54 ip4:54.240.43.16 include:_spf.salesforce.com ip4:209.144.103.186 include:spf.mandrillapp.com -all

    See what this looks like →

  • Looks fine

    present with p=reject

    A policy that actually instructs receivers, which is more than most senders publish.

    v=DMARC1; p=reject; adkim=r; aspf=r; pct=100; rua=mailto:dmarc_rua@emaildefense.proofpoint.com,mailto:dmarc@npr.org;

    From DMARC p=none is monitoring, not enforcementSee what this looks like →

  • Looks fine

    keys published on 5 selectors

    A key existing is not the same as working. Read a real received header and check the d= value matches your before you call this done.

    k2._domainkey (Mailchimp), mandrill._domainkey (Mandrill), selector1._domainkey (Microsoft 365), s2._domainkey (SendGrid), s1._domainkey (SendGrid)

    From DKIM passing is not DKIM alignedSee what this looks like →

    Part platform, part you

    The key is your platform's to publish and it has. Whether it signs the domain in your is yours to confirm, and cannot show it — send one campaign to yourself and look for =pass header.d=npr.org in the Authentication-Results header.

  • Context

    SendGrid signs your mail, and your cannot be read to confirm it

    2 of SendGrid's selectors carry live keys on this domain, so SendGrid is signing mail as you. Whether your authorises it is not answerable by reading . Your record uses SPF macros (Proofpoint), so the authorised senders are resolved per message from the connecting IP and are never published as a list. No checker can settle it from DNS, including this one — anyone who tells you this record does or does not list SendGrid is guessing.

    v=spf1 include:spf-0032f701.pphosted.com include:spf.protection.outlook.com include:prss.org exists:%{i}._spf.mta.salesforce.com include:c9eb27a2d7.berenice.eoidentity.com ip4:64.124.132.59/32 ip4:66.150.167.192/27 ip4:162.242.229.170 ip4:205.153.38.0/24 ip4:205.153.36.170 ip4:40.107.0.0/16 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.0.0/16 ip4:139.60.0.0/24 ip4:139.60.1.0/24 ip4:139.60.2.0/24 ip4:139.60.3.0/24 ip4:13.111.0.0/16 ip4:136.147.135.0/24 ip4:136.147.176.0/24 ip4:136.147.182.0/24 ip4:198.245.81.0/24 ip4:199.122.123.0/24 ip4:195.66.99.135 ip4:212.227.89.57 ip4:217.160.226.166 ip4:54.194.192.132 ip4:62.75.247.44 ip4:82.165.193.1 ip4:85.25.144.9 ip4:87.79.30.25 ip4:87.79.30.30 ip4:208.86.168.7 ip4:135.84.68.123 ip4:206.152.14.54 ip4:54.240.43.16 include:_spf.salesforce.com ip4:209.144.103.186 include:spf.mandrillapp.com -all

    From Gmail enforces authentication, PTR, TLS and a 0.30 percent spam rateSee what this looks like →

    Good to know — nothing to fix

    Send one real campaign through SendGrid and read the Authentication-Results header on what arrives. That header is the only place this question gets answered, because it is the receiver evaluating the macro against the real .

  • Context

    record published

    Your logo can appear in supporting clients, which needs at quarantine or reject.

    See what this looks like →

  • Context

    MX records present

    Where you receive mail says nothing about where you send it. Marketing sends usually leave through a different platform entirely.

    mxa-0032f701.gslb.pphosted.com, mxb-0032f701.gslb.pphosted.com

    See what this looks like →

What has moved

One entry per day a published record actually changed. Days we looked and found nothing different are counted, not listed.

  1. First observation — what was already published

    SPF published.

    v=spf1 include:spf-0032f701.pphosted.com include:spf.protection.outlook.com include:prss.org exists:%{i}._spf.mta.salesforce.com include:c9eb27a2d7.berenice.eoidentity.com ip4:64.124.132.59/32 ip4:66.150.167.192/27 ip4:162.242.229.170 ip4:205.153.38.0/24 ip4:205.153.36.170 ip4:40.107.0.0/16 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.0.0/16 ip4:139.60.0.0/24 ip4:139.60.1.0/24 ip4:139.60.2.…

    DMARC published.

    v=DMARC1; p=reject; adkim=r; aspf=r; pct=100; rua=mailto:dmarc_rua@emaildefense.proofpoint.com,mailto:dmarc@npr.org;

    DKIM keys on selectors we probe.

    k2._domainkey (Mailchimp), mandrill._domainkey (Mandrill), s1._domainkey (SendGrid), s2._domainkey (SendGrid), selector1._domainkey (Microsoft 365)

    BIMI published.

    v=BIMI1; l=https://legacy.npr.org/assets/bimi/order_161790599_logo.svg; a=https://legacy.npr.org/assets/bimi/national_public_radio_inc.pem;

    MX records present.

    mxa-0032f701.gslb.pphosted.com, mxb-0032f701.gslb.pphosted.com
Where this comes from. Public DNS, and nothing else. We read the same TXT and MX records any mail server reads before accepting a message, on the days someone looked. There is no scan, no login, no mail, and no score here — only what was published and the date we saw it. Gaps are days we did not get a clean answer from a resolver, and we would rather leave those blank than guess at them.