openai.com email security: SPF, DKIM & DMARC

Is openai.com spoofable? See openai.com's SPF, DKIM, DMARC and MTA-STS records and find out if this domain is protected against email spoofing.

Last updated: June 3, 2026

90A
This domain is protected against spoofing

SPF

OK
v=spf1 include:_spf.google.com include:spf.protection.outlook.com include:8050860.spf04.hubspotemail.net include:mktomail.com include:spf_c.oraclecloud.com -all

DKIM

OK
Selectors: google, selector1, s1, s2

DMARC

OK
v=DMARC1; p=reject; rua=mailto:tdfyvl0n@ag.dmarcian.com; ruf=mailto:tdfyvl0n@fr.dmarcian.com; fo=1; aspf=r

MX

OK
aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt4.aspmx.l.google.com, alt3.aspmx.l.google.com

MTA-STS

Missing

No record found

Read the guide

Recommendations

  1. 1Add MTA-STS to enforce TLS encryption for incoming emails

    Without MTA-STS, an attacker performing a man-in-the-middle attack can downgrade the connection between mail servers to plaintext, intercepting emails in transit. MTA-STS tells sending servers to only deliver via TLS with a valid certificate, preventing downgrade attacks.

Run a live analysis

The results above are updated daily. For an instant check of openai.com, run a live analysis.

Analyze openai.com live

Frequently asked questions about openai.com

Is openai.com spoofable?

No. openai.com is protected against email spoofing with a robust configuration. Email security score: 90/100 (grade A).

Does openai.com have an SPF record?

Yes, openai.com publishes an SPF record (-all qualifier).

What is openai.com's DMARC record?

openai.com publishes a DMARC record (_dmarc.openai.com) with a p=reject policy.

Does openai.com use DKIM?

Yes, DKIM signatures were detected for openai.com.

Want to test another domain? Run a free email spoofing test.

Guides to understand these results

Check other domains