Email authentication check

twitch.tv

This check reviews the domain's email authentication setup to help protect against spoofing and phishing.

All data is public, sourced from DNS Last checked about 23 hours ago
At risk

twitch.tv has authentication gaps that can expose the domain to spoofing.

Start by publishing valid SPF and DMARC records, then add reporting and optional brand or transport protections.

55 out of 110
0 of 4 checks passed
Last checked about 23 hours ago
Compare with other domains

DMARC

Optional

Domain-based Message Authentication

45 / 50

Strict reject policy enforced

DMARC record is valid and configured correctly.

_dmarc.twitch.tv TXT
v=DMARC1; p=reject; adkim=s; aspf=s; fo=1; ri=3600; rua=mailto:[email protected]; ruf=mailto:[email protected]

Score breakdown

  • DMARC record published +10
  • Syntax valid +5
  • Reject policy (maximum protection) +20
  • Aggregate reporting (rua) configured with issues +7
  • Failure reporting (ruf) configured with issues +3

Configuration

Policy (p)
reject
DKIM alignment (adkim)
Strict (s)
SPF alignment (aspf)
Strict (s)
Subdomain policy (sp)
Inherits p=reject
Failure reporting (fo)
1

Reporting (RUA / RUF)

Aggregate reports Optional
External domain verification needs attention
Failure reports Optional
External domain verification needs attention
RFC 9989 note on p=reject
RFC 9989 cautions against p=reject for domains whose users post to mailing lists, and §7.4 requires receivers to treat p=reject as p=quarantine unless their own analysis justifies rejecting. For transactional or marketing-only domains, p=reject stays appropriate; mailbox domains should consider p=quarantine with sp=reject on non-sending subdomains.
Record uses tags removed by RFC 9989
RFC 9989 (May 2026) removed the ri tag. Receivers send aggregate reports daily regardless.
External domain verification issues
RUA (Aggregate Reports) external domain verification failed RUF (failure reports) external domain verification failed

SPF

Failed

Sender Policy Framework

10 / 30

SPF record has configuration errors

SPF record is invalid due to exceeding DNS lookup limit (10) per RFC 7208.

twitch.tv TXT
v=spf1 include:_spf.google.com include:amazonses.com include:_spf.twitch.tv include:aspmx.pardot.com a mx -all

Score breakdown

  • SPF record published +10
  • Syntax valid 0 / 5

Configuration

Default policy
-all (hard fail)
DNS lookups
12 / 10 max
Void lookups
0 / 2 max
Syntax check
OK

DNS lookup detail

Each mechanism that may trigger a DNS query at delivery time.

1 include: _spf.google.com Valid

SPF record found

v=spf1 ip4:74.125.0.0/16 ip4:209.85.128.0/17 ip6:2001:4860:4864::/56 ip6:2404:6800:4864::/56 ip6:2607:f8b0:4864::/56 ip6:2800:3f0:4864::/56 ip6:2a00:1450:4864::/56 ip6:2c0f:fb50:4864::/56 ~all

Processed recursively per RFC 7208

2 include: amazonses.com Valid

SPF record found

v=spf1 ip4:199.255.192.0/22 ip4:199.127.232.0/22 ip4:54.240.0.0/18 ip4:69.169.224.0/20 ip4:23.249.208.0/20 ip4:23.251.224.0/19 ip4:76.223.176.0/20 ip4:54.240.64.0/18 ip4:76.223.128.0/19 ip4:216.221.160.0/19 ip4:206.55.144.0/20 ip4:24.110.64.0/18 -all

Processed recursively per RFC 7208

3 include: _spf.twitch.tv Valid

SPF record found

v=spf1 ip4:99.181.116.5 ip4:99.181.116.246 ip4:99.181.72.37 ip4:99.181.72.12 ip4:52.73.203.75 ip4:67.207.130.212 ip4:69.38.212.114 ip4:52.223.252.128/27 ip4:52.223.252.160/27 ip4:167.89.64.215 ~all

Processed recursively per RFC 7208

4 include: aspmx.pardot.com Valid

SPF record found

v=spf1 include:et._spf.pardot.com -all

Processed recursively per RFC 7208

5 include: et._spf.pardot.com Valid

SPF record found

v=spf1 ip4:198.245.81.0/24 ip4:136.147.176.0/24 ip4:13.111.0.0/16 ip4:136.147.182.0/24 ip4:136.147.135.0/24 ip4:199.122.123.0/24 -all

Processed recursively per RFC 7208

6 a: twitch.tv Resolved

A/AAAA records found: 4

7 mx: twitch.tv Resolved

MX records found: 5

MX records

aspmx.l.google.com (priority: 10)

alt1.aspmx.l.google.com (priority: 20)

alt2.aspmx.l.google.com (priority: 30)

aspmx2.googlemail.com (priority: 40)

aspmx3.googlemail.com (priority: 50)

Authorized IP addresses

include:_spf.google.com

74.125.0.0/16 209.85.128.0/17 2001:4860:4864::/56 2404:6800:4864::/56 2607:f8b0:4864::/56 2800:3f0:4864::/56 2a00:1450:4864::/56 2c0f:fb50:4864::/56

include:amazonses.com

199.255.192.0/22 199.127.232.0/22 54.240.0.0/18 69.169.224.0/20 23.249.208.0/20 23.251.224.0/19 76.223.176.0/20 54.240.64.0/18 76.223.128.0/19 216.221.160.0/19 206.55.144.0/20 24.110.64.0/18

include:_spf.twitch.tv

99.181.116.5 99.181.116.246 99.181.72.37 99.181.72.12 52.73.203.75 67.207.130.212 69.38.212.114 52.223.252.128/27 52.223.252.160/27 167.89.64.215

include:et._spf.pardot.com

198.245.81.0/24 136.147.176.0/24 13.111.0.0/16 136.147.182.0/24 136.147.135.0/24 199.122.123.0/24
SPF configuration warning
DNS lookups may exceed the RFC 7208 limit (10) in worst-case evaluation.

BIMI

Optional

Brand Indicators for Message Identification

0 / 20

No BIMI record published

No BIMI record found for selector 'default'.

Score breakdown

  • BIMI record published (optional) 0 / 5

Configuration

Logo (l)
Not configured
Mark certificate (a)
Not configured
Selector
default
Note
SVG content is not parsed, for safety
BIMI is optional
BIMI usually matters after DMARC enforcement is working. Use it for brand display, not as a replacement for SPF or DMARC.

TLS

Optional

Transport security · MTA-STS & TLS-RPT

0 / 10

Inbound transport protection not fully configured

MTA-STS and TLS-RPT are optional, but they protect inbound mail against transport downgrade attacks and give visibility into TLS delivery failures.

Score breakdown

  • TLS-RPT record configured (optional) 0 / 5
  • MTA-STS policy configured (optional) 0 / 5

Configuration

TLS-RPT
Not configured
MTA-STS
Not configured

Transport checks

TLS-RPT (reporting) Not configured

No TLS-RPT record found.

MTA-STS (policy) Not configured

No MTA-STS record found.

Protect inbound transport

Receiver Shield helps deploy, monitor, and safely enforce MTA-STS and TLS-RPT for twitch.tv.

Start monitoring

twitch.tv enforces a strict DMARC reject policy, instructing receivers to block unauthenticated emails. The SPF record contains errors that may cause legitimate emails to fail authentication. twitch.tv's email authentication needs attention to reduce spoofing risk.

Keep twitch.tv protected automatically

This check is a snapshot. DNS records drift when providers change, teams edit records, or unauthorized changes slip in. DMARCTrust watches the same authentication layer continuously and tells you when something moves.

DMARC report processing

Aggregate and failure DMARC reports are received, parsed, and turned into sender visibility without manual XML handling.

DNS change alerts

DNS checks run every 5 minutes for monitored domains, with email alerts when DMARC, SPF, BIMI, TLS-RPT, or MTA-STS records change.

Receiver Shield for inbound

Deploy, host, and safely enforce MTA-STS and TLS-RPT when this checker finds an inbound transport gap.

Start monitoring twitch.tv View plans First checked 6 months ago

Check another domain

Run a free email authentication check: DMARC, SPF, BIMI, TLS-RPT, and MTA-STS.

Try a popular example: google.com, amazon.com, booking.com
Explore

How other domains configure email authentication

Showing domains checked by our users. All data is from public DNS records.

Popular domains

Frequently checked

Well configured

Reject policy + valid SPF

Same policy

Also using reject

What we check

DMARC policy and alignment, SPF record and includes, BIMI logo and certificate, and inbound transport security with MTA-STS and TLS-RPT.

Why it matters

Healthy authentication improves delivery and blocks spoofing. Major inbox providers increasingly expect DMARC and aligned SPF or DKIM from senders.

What you get

Syntax, policy, reporting validation, include analysis, alignment interpretation, and clear setup guidance for every result.