SPF Check:
_spf1.intuit.com

1. Specify domain name

Enter a domain to be checked for the SPF record
2. Specify IP address (optional)
Enter any IP address to check if it is authorized to send e-mails by the SPF record

What is the SPF lookup for?

With the SPF lookup you analyze the SPF record of a domain for errors, security risks and authorized IP addresses. Optionally, you can specify an IP address to check if it is authorized to send e-mail on behalf of the domain. The SPF lookup analyzes registered TXT records in real time. If you want to specify an SPF record manually, use the SPF Analyzer.

Loading...

SPF check passed

Your SPF record check result
  •   SPF record found
  •   Syntax check: 0 errors
  •   Email Anti-Spoofing: Good
Warning: Compliance breach for email deliverability & security

The domain _spf1.intuit.com does not fulfil the requirements for optimal deliverability to Google, Yahoo and other email service providers.

Mandatory IT baseline protection measures for email security are not fulfilled. There are risks of email misuse.

Summary of the SPF check

Does a valid SPF record exist?
An SPF record was found for the domain _spf1.intuit.com.
The SPF record for _spf1.intuit.com is valid.
The syntax check of the SPF record shows no obvious errors.

Which IP-s are legitimate to send emails?
The SPF record contains a reference to external rules, which means that the validity of the SPF record depends on at least one other domain. A detailed list of the rules used externally can be found in the analysis result. In total, 56 IP address(es) were authorized by the SPF record to send emails.

The SPF record analysis was performed on 22.12.2024 at 07:41:05 clock.

Lookup for the domain:
_spf1.intuit.com
IP address to be checked:
no IP address specified
Solve your problems in no time
Guaranteed measurable improvement for email deliverability and domain security
Solve your problems in no time

Evaluation for the domain _spf1.intuit.com 

Nameserverset:
a1-182.akam.net
dns1.p01.nsone.net
dns2.p01.nsone.net
dns3.p01.nsone.net
dns4.p01.nsone.net
a7-66.akam.net
a24-67.akam.net
a11-64.akam.net
a18-64.akam.net
a6-66.akam.net
Determined SPF record:
Legitimated IP addresses:
IP Provider / ASN DNSBL-Check
40.92.0.0/15
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
40.107.0.0/16
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
52.100.0.0/15
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
52.102.0.0/16
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
52.103.0.0/17
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
104.47.0.0/17
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
2a01:111:f400::/48
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
2a01:111:f403::/49
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
2a01:111:f403:8000::/51
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
2a01:111:f403:c000::/51
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
2a01:111:f403:f000::/52
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
23.253.182.103 RACKSPACE blacklist 
23.253.183.145 RACKSPACE blacklist 
23.253.183.146 RACKSPACE blacklist 
23.253.183.147 RACKSPACE blacklist 
23.253.183.148 RACKSPACE blacklist 
23.253.183.150 RACKSPACE blacklist 
166.78.68.221 RACKSPACE blacklist 
167.89.46.159 SENDGRID blacklist 
167.89.64.9 SENDGRID blacklist 
167.89.65.0 SENDGRID blacklist 
167.89.65.53 SENDGRID blacklist 
167.89.65.100 SENDGRID blacklist 
167.89.74.233 SENDGRID blacklist 
167.89.75.33 SENDGRID blacklist 
167.89.75.126 SENDGRID blacklist 
167.89.75.136 SENDGRID blacklist 
167.89.75.164 SENDGRID blacklist 
192.237.159.42 RACKSPACE blacklist 
192.237.159.43 RACKSPACE blacklist 
159.112.242.162 MAILGUN blacklist 
159.135.228.10 MAILGUN blacklist 
103.151.192.0/23
AMAZON-02 blacklist 
185.12.80.0/22
- blacklist 
188.172.128.0/20
- blacklist 
192.161.144.0/20
- blacklist 
216.198.0.0/18
AMAZON-02 blacklist 
139.138.35.44 IRONPORT-SYSTEMS-INC blacklist 
139.138.46.121 IRONPORT-SYSTEMS-INC blacklist 
139.138.46.176 IRONPORT-SYSTEMS-INC blacklist 
139.138.46.219 IRONPORT-SYSTEMS-INC blacklist 
139.138.57.55 IRONPORT-SYSTEMS-INC blacklist 
139.138.58.119 IRONPORT-SYSTEMS-INC blacklist 
216.71.138.33 IRONPORT-SYSTEMS-INC blacklist 
68.232.140.138 IRONPORT-SYSTEMS-INC blacklist 
107.20.210.250 AMAZON-AES blacklist 
52.1.14.157 AMAZON-AES blacklist 
12.216.231.16 ATT-INTERNET4 blacklist 
12.187.184.48 ATT-INTERNET4 blacklist 
12.149.174.0/27
ATT-INTERNET4 blacklist 
12.187.184.32/28
ATT-INTERNET4 blacklist 
12.216.231.32/28
ATT-INTERNET4 blacklist 
199.16.137.0/24
- blacklist 
199.16.139.0/25
- blacklist 
206.225.202.0/27
- blacklist 
206.225.218.0/27
- blacklist 
SPF-Syntax Check:
Analysis result of the SPF record for the domain: _spf1.intuit.com

SPF record available?

We found an SPF record for the domain.

v=spf1

Additionally authorized IPv4 addresses

Explicit IPv4 addresses in the SPF record have been authorized to send

12.216.231.16
12.187.184.48
12.149.174.0/27
12.187.184.32/28
12.216.231.32/28
199.16.137.0/24
199.16.139.0/25
206.225.202.0/27
206.225.218.0/27

Additional external SPF records

We could find other records authorized in the SPF record

include:spf.protection.outlook.com
v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all
ipv4:
40.92.0.0/15
ipv4:
40.107.0.0/16
ipv4:
52.100.0.0/15
ipv4:
52.102.0.0/16
ipv4:
52.103.0.0/17
ipv4:
104.47.0.0/17
ipv6:
2a01:111:f400::/48
ipv6:
2a01:111:f403::/49
ipv6:
2a01:111:f403:8000::/51
ipv6:
2a01:111:f403:c000::/51
ipv6:
2a01:111:f403:f000::/52
include:_spf2.intuit.com
v=spf1 include:stspg-customer.com include:mail.zendesk.com ip4:139.138.35.44 ip4:139.138.46.121 ip4:139.138.46.176 ip4:139.138.46.219 ip4:139.138.57.55 ip4:139.138.58.119 ip4:216.71.138.33 ip4:68.232.140.138 ip4:107.20.210.250 ip4:52.1.14.157 ~all
ipv4:
139.138.35.44
ipv4:
139.138.46.121
ipv4:
139.138.46.176
ipv4:
139.138.46.219
ipv4:
139.138.57.55
ipv4:
139.138.58.119
ipv4:
216.71.138.33
ipv4:
68.232.140.138
ipv4:
107.20.210.250
ipv4:
52.1.14.157
include:stspg-customer.com
v=spf1 ip4:23.253.182.103 ip4:23.253.183.145 ip4:23.253.183.146 ip4:23.253.183.147 ip4:23.253.183.148 ip4:23.253.183.150 ip4:166.78.68.221 ip4:167.89.46.159 ip4:167.89.64.9 ip4:167.89.65.0 ip4:167.89.65.53 ip4:167.89.65.100 ip4:167.89.74.233 ip4:167.89.75.33 ip4:167.89.75.126 ip4:167.89.75.136 ip4:167.89.75.164 ip4:192.237.159.42 ip4:192.237.159.43 ip4:159.112.242.162 ip4:159.135.228.10 -all
ipv4:
23.253.182.103
ipv4:
23.253.183.145
ipv4:
23.253.183.146
ipv4:
23.253.183.147
ipv4:
23.253.183.148
ipv4:
23.253.183.150
ipv4:
166.78.68.221
ipv4:
167.89.46.159
ipv4:
167.89.64.9
ipv4:
167.89.65.0
ipv4:
167.89.65.53
ipv4:
167.89.65.100
ipv4:
167.89.74.233
ipv4:
167.89.75.33
ipv4:
167.89.75.126
ipv4:
167.89.75.136
ipv4:
167.89.75.164
ipv4:
192.237.159.42
ipv4:
192.237.159.43
ipv4:
159.112.242.162
ipv4:
159.135.228.10
include:mail.zendesk.com
v=spf1 ip4:103.151.192.0/23 ip4:185.12.80.0/22 ip4:188.172.128.0/20 ip4:192.161.144.0/20 ip4:216.198.0.0/18 ~all
ipv4:
103.151.192.0/23
ipv4:
185.12.80.0/22
ipv4:
188.172.128.0/20
ipv4:
192.161.144.0/20
ipv4:
216.198.0.0/18

E-Mail handling

How should the checkHost() function of the e-mail server handle the e-mail? (syntax )

~all
SoftFail (non-compliant e-mails are accepted but marked)

Will be forwarded to another SPF record?

There is no reference to any other SPF record

Are the server addresses allowed to send e-mails?

In the SPF entry the mechanism 'a' has not been set.

Additionally authorized A-records?

In addition to the A-Records stored in the DNS, we could not find any other records authorized in the SPF-Record.

Are the registered mail servers allowed to send e-mails?

In the SPF entry the mechanism 'mx' has not been set

Additionally authorized MX records

We could not find any other records authorized in the SPF record besides the MX records stored in the DNS

Additionally authorized IPv6 addresses

No explicit IPv6 addresses in the SPF record have been authorised to send

How is the sender informed?

The exp mechanism acts as a return to the sender if the IP address was not authorized to send and notify them. None was found.

PTR (obsolete mechanism)

The ptr mechanism is deprecated, slow and insecure and should not be used

PTR:

The ptr mechanism is deprecated, slow and insecure and should not be used

Authorize IP addresses with markers

When SPF is evaluated, macros can specifically authorize Ip addresses based on the request or connection of the user or client (RFC7208 )

Receiver address

analysis.ra-missing

Amount of reports

analysis.rp-missing

Report selection

analysis.rr-missing

Unknown mechanisms

No unknown mechanisms were found in the SPF record.

Recently performed SPF lookups

Server IP Address

We have determined the following IP address for the domain:

No domain specified

Reverse address

We have determined the following name for the server IP address:

No PTR record found

Free whitepaper

How secure is your domain?

  • Practical with many examples
  • the basics of domain risk management summarized in 20 pages
  • Checklist with 53 questions on 14 risk areas

Get a first impression of the risk potential in your company

⮩ Download "Domain Risk Management" for free
All offers are aimed at traders, not end consumers and do not include VAT.
© 2024 nicmanager.com.   All rights reserved.
nicmanager