gitlab.com
Poor, with 2 things to fix
gitlab.com scored 59/100 (grade D). The main issues are SPF needs more than 10 DNS lookups and DKIM key shorter than 2048 bits, plus 1 more. Detected senders: Google Workspace, Mailgun, Zendesk and Salesforce.
Checked 2026-10-04 02:08 UTC · fresh check
Reduce SPF DNS lookups
Evaluating SPF for gitlab.com takes 11 DNS lookups including nested includes; receivers stop at 10 and fail SPF. No detected sending service accounts for these includes; remove each one you no longer send through: mktomail.com, _spf-ip.gitlab.com, _spf.sendergen.com.
gitlab.com
Some DNS providers want “@” here instead of the full domain.
v=spf1 include:mail.zendesk.com include:_spf.google.com include:mktomail.com include:_spf.salesforce.com include:_spf-ip.gitlab.com a:zgateway.zuora.com include:mailgun.org include:_spf.sendergen.com ip4:35.80.141.6/32 ip4:44.229.121.55/32 -all
v=spf1 include:mail.zendesk.com include:_spf.google.com include:mktomail.com include:_spf.salesforce.com include:_spf-ip.gitlab.com a:zgateway.zuora.com include:mailgun.org include:_spf.sendergen.com ip4:35.80.141.6/32 ip4:44.229.121.55/32 -all
How to apply it
- Sign in where your domain’s DNS is managed. This is often where you bought the domain, such as Cloudflare, GoDaddy or Namecheap.
- Find the existing TXT record with that name and replace its value.
- Save, then come back and re-check. DNS changes can take up to a few hours to show.
All checks
MXCan servers find your inbox?No issues foundPass
Nothing to report.
SPFWho may send as you?SPF needs more than 10 DNS lookupsFailing
- Fail: SPF needs more than 10 DNS lookups
Evaluating the SPF record for gitlab.com needs more than 10 DNS lookups (counting nested includes). Receivers stop at 10 with a permanent error, so SPF fails. Remove unused includes or replace them with IP ranges.
How to fix this - Warning: SPF has no "all" term
Without a closing "all" term, mail from unlisted servers gets a neutral result. End the record with "-all" or "~all".
DKIMAre your emails signed?DKIM key shorter than 2048 bitsNeeds attention
- Warning: DKIM key shorter than 2048 bits
google (1024-bit), k1 (1024-bit), mail (1024-bit) uses an RSA key below 2048 bits. Short keys can be factored and some receivers treat them as weak. Rotate to a 2048-bit key at your sending provider.
- Pass: DKIM key published
gitlab.com publishes a DKIM key under google, k1, mail.
DMARCWhat happens to fakes?No issues foundPass
Nothing to report.
AlignmentDoes it match your From?SPF alignment is unknownInfo
- Info: SPF alignment is unknown
The SPF record of gitlab.com can pass for some senders (those matched before the failing part), but another evaluation path ends in a permanent error (spf.lookups.over-limit). Senders that reach that path fail SPF, so whether your mail aligns through SPF is unknown. Fix the error so every path evaluates.
BIMICan inboxes show your logo?No BIMI recordInfo
- Info: No BIMI record
No BIMI record at default._bimi.gitlab.com. BIMI is optional: it shows your logo next to your mail in supporting inboxes once DMARC is enforced.
How to fix this
MTA-STSIs mail to you encrypted?No MTA-STS recordInfo
- Info: No MTA-STS record
No MTA-STS record at _mta-sts.gitlab.com. MTA-STS (RFC 8461) makes sending servers require TLS and a valid certificate when delivering to you, which blocks downgrade attacks.
How to fix this
TLS-RPTWill you hear about failures?No TLS-RPT recordInfo
- Info: No TLS-RPT record
No TLS reporting record at _smtp._tls.gitlab.com. TLS-RPT (RFC 8460) tells senders where to send daily reports about failed encrypted deliveries to you.
How to fix this
Other fixes
Publish the MTA-STS recordTXT
Tells sending servers that gitlab.com publishes an MTA-STS policy at https://mta-sts.gitlab.com/.well-known/mta-sts.txt. Change the id whenever the policy file changes.
_mta-sts.gitlab.com
Some DNS providers want just “_mta-sts” here.
v=STSv1; id=202610040208
Host the MTA-STS policy filepolicy-file
Serve this file over HTTPS with a valid certificate for mta-sts.gitlab.com. It lists your MX hosts and starts in testing mode; switch to mode: enforce once TLS-RPT reports show no failures.
https://mta-sts.gitlab.com/.well-known/mta-sts.txt
version: STSv1 mode: testing mx: aspmx.l.google.com mx: alt1.aspmx.l.google.com mx: alt2.aspmx.l.google.com mx: alt3.aspmx.l.google.com mx: alt4.aspmx.l.google.com max_age: 604800
Set up a TLS report addressinstruction
Sending servers will report TLS failures when delivering to gitlab.com, which you need before enforcing MTA-STS. The address must accept TLS reports; a DMARC report address does not necessarily do so.
Applies to: _smtp._tls.gitlab.com
- Pick an address that will receive TLS reports: a mailbox you read (for example tls-reports@gitlab.com, created first) or a TLS reporting service. 2. Publish a TXT record at _smtp._tls.gitlab.com with the value v=TLSRPTv1; rua=mailto:<that address>.
Prepare BIMIinstruction
BIMI shows your logo next to messages in supporting inboxes, but only for mail that passes DMARC under an enforced policy.
Applies to: default._bimi.gitlab.com
- Enforce DMARC first: p=quarantine or p=reject at 100% (no pct below 100). 2. Convert your logo to an SVG Tiny PS file and host it over HTTPS, for example https://gitlab.com/bimi/logo.svg. 3. For Gmail and Apple Mail, obtain a VMC or CMC certificate for the logo. 4. Publish a TXT record at default._bimi.gitlab.com with v=BIMI1, l= set to the logo URL and a= set to the certificate URL.