Authentication history · 59 days observed
substack.com
Observed from 4 Aug 2026 to 3 Oct 2026. Nothing published in DNS has moved in that window.
Where it stands today
Live lookup, 3 Oct 2026. The same check /check/substack.com runs.
- 3fine
- 1context
Looks fine
present, ending ~all
Soft fail. Accepted everywhere, though -all is stronger once your sender list is complete.
v=spf1 include:_spf.google.com include:mailgun.org include:mail.zendesk.com ~all
Looks fine
present with p=reject
A policy that actually instructs receivers, which is more than most senders publish.
v=DMARC1; p=reject; pct=100; rua=mailto:re+kvnosxqvppz@dmarc.postmarkapp.com; sp=reject; aspf=r;
From DMARC p=none is monitoring, not enforcementSee what this looks like →
Looks fine
keys published on 1 selector
A key existing is not the same as working. Read a real received header and check the d= value matches your before you call this done.
google._domainkey (Google Workspace)
From DKIM passing is not DKIM alignedSee what this looks like →
Part platform, part you
The key is your platform's to publish and it has. Whether it signs the domain in your is yours to confirm, and cannot show it — send one campaign to yourself and look for =pass header.d=substack.com in the Authentication-Results header.
Context
MX records present
Where you receive mail says nothing about where you send it. Marketing sends usually leave through a different platform entirely.
mxa.mailgun.org, mxb.mailgun.org
What has moved
One entry per day a published record actually changed. Days we looked and found nothing different are counted, not listed.
First observation — what was already published
SPF published.
v=spf1 include:_spf.google.com include:mailgun.org include:mail.zendesk.com ~all
DMARC published.
v=DMARC1; p=reject; pct=100; rua=mailto:re+kvnosxqvppz@dmarc.postmarkapp.com; sp=reject; aspf=r;
DKIM keys on selectors we probe.
google._domainkey (Google Workspace)
MX records present.
mxa.mailgun.org, mxb.mailgun.org