hcaptcha.com

hcaptcha.com · Last checked 2026-10-04 02:07 UTC

hcaptcha.com

Good, with 2 things to fix

hcaptcha.com scored 84/100 (grade B). The main issues are DKIM key shorter than 2048 bits and SPF is close to the 10-lookup limit. Detected senders: Google Workspace, Amazon SES, HubSpot, Mailgun, Customer.io and Zendesk.

Checked 2026-10-04 02:07 UTC · fresh check

4 passed2 need attention0 failing2 for informationDetected senders: Google Workspace, Amazon SES, HubSpot, Mailgun, Customer.io, Zendesk
Fix this firstThe change with the biggest effect

Reduce SPF DNS lookups

Evaluating SPF for hcaptcha.com takes 10 DNS lookups including nested includes; receivers stop at 10 and fail SPF. Every include belongs to a detected provider; move some senders to a subdomain with its own SPF record. Changes: Added include:_spf.google.com for Google Workspace. HubSpot has no SPF include to add; it authenticates through its own return-path domain or DKIM. Replaced ~all with -all so mail from servers not listed is rejected.

TypeTXT
Name / Host
hcaptcha.com

Some DNS providers want “@” here instead of the full domain.

Value
v=spf1 include:mailgun.org include:amazonses.com include:us-west-2.amazonses.com include:mail.zendesk.com include:20974113.spf07.hubspotemail.net include:_spf.google.com -all
Replaces
v=spf1 include:mailgun.org include:amazonses.com include:us-west-2.amazonses.com include:mail.zendesk.com include:20974113.spf07.hubspotemail.net ~all

How to apply it

  1. Sign in where your domain’s DNS is managed. This is often where you bought the domain, such as Cloudflare, GoDaddy or Namecheap.
  2. Find the existing TXT record with that name and replace its value.
  3. Save, then come back and re-check. DNS changes can take up to a few hours to show.

All checks

MXCan servers find your inbox?No issues foundPass

Nothing to report.

SPFWho may send as you?SPF is close to the 10-lookup limitNeeds attention
  • Warning: SPF is close to the 10-lookup limit

    Evaluating the SPF record for hcaptcha.com needs 10 of the 10 allowed DNS lookups. Adding one more service, or a provider growing its own record, will break SPF.

    How to fix this
  • Info: SPF ends in softfail (~all)

    "~all" is common and works well with DMARC. "-all" is stricter; switch when you are sure every sender is listed.

DKIMAre your emails signed?DKIM key shorter than 2048 bitsNeeds attention
  • Warning: DKIM key shorter than 2048 bits

    krs (1024-bit) uses an RSA key below 2048 bits. Short keys can be factored and some receivers treat them as weak. Rotate to a 2048-bit key at your sending provider.

  • Pass: DKIM key published

    hcaptcha.com publishes a DKIM key under krs.

DMARCWhat happens to fakes?No issues foundPass

Nothing to report.

AlignmentDoes it match your From?SPF alignment depends on a custom Return-PathInfo
  • Info: SPF alignment depends on a custom Return-Path

    This is a heuristic. Your SPF record only authorizes third-party senders (mailgun.org, _spf.mailgun.org, _spf1.mailgun.org, _spf2.mailgun.org, _spf.eu.mailgun.org, amazonses.com, us-west-2.amazonses.com, mail.zendesk.com, 20974113.spf07.hubspotemail.net). By default they bounce from their own Return-Path domain, and SPF then passes for that domain, not hcaptcha.com. Even relaxed alignment needs the Return-Path's organizational domain to be hcaptcha.com, so set up a custom Return-Path (bounce) domain under hcaptcha.com with each provider, and sign with DKIM as hcaptcha.com.

BIMICan inboxes show your logo?No BIMI recordInfo
  • Info: No BIMI record

    No BIMI record at default._bimi.hcaptcha.com. BIMI is optional: it shows your logo next to your mail in supporting inboxes once DMARC is enforced.

    How to fix this
MTA-STSIs mail to you encrypted?No issues foundPass

Nothing to report.

TLS-RPTWill you hear about failures?TLS-RPT is configuredPass
  • Pass: TLS-RPT is configured

    TLS reports will be sent to mailto:security@hcaptcha.com.

Other fixes

Prepare BIMIinstruction

BIMI shows your logo next to messages in supporting inboxes, but only for mail that passes DMARC under an enforced policy.

Applies to: default._bimi.hcaptcha.com

  1. Enforce DMARC first: p=quarantine or p=reject at 100% (no pct below 100). 2. Convert your logo to an SVG Tiny PS file and host it over HTTPS, for example https://hcaptcha.com/bimi/logo.svg. 3. For Gmail and Apple Mail, obtain a VMC or CMC certificate for the logo. 4. Publish a TXT record at default._bimi.hcaptcha.com with v=BIMI1, l= set to the logo URL and a= set to the certificate URL.