hcaptcha.com
Good, with 2 things to fix
hcaptcha.com scored 84/100 (grade B). The main issues are DKIM key shorter than 2048 bits and SPF is close to the 10-lookup limit. Detected senders: Google Workspace, Amazon SES, HubSpot, Mailgun, Customer.io and Zendesk.
Checked 2026-10-04 02:07 UTC · fresh check
Reduce SPF DNS lookups
Evaluating SPF for hcaptcha.com takes 10 DNS lookups including nested includes; receivers stop at 10 and fail SPF. Every include belongs to a detected provider; move some senders to a subdomain with its own SPF record. Changes: Added include:_spf.google.com for Google Workspace. HubSpot has no SPF include to add; it authenticates through its own return-path domain or DKIM. Replaced ~all with -all so mail from servers not listed is rejected.
hcaptcha.com
Some DNS providers want “@” here instead of the full domain.
v=spf1 include:mailgun.org include:amazonses.com include:us-west-2.amazonses.com include:mail.zendesk.com include:20974113.spf07.hubspotemail.net include:_spf.google.com -all
v=spf1 include:mailgun.org include:amazonses.com include:us-west-2.amazonses.com include:mail.zendesk.com include:20974113.spf07.hubspotemail.net ~all
How to apply it
- Sign in where your domain’s DNS is managed. This is often where you bought the domain, such as Cloudflare, GoDaddy or Namecheap.
- Find the existing TXT record with that name and replace its value.
- Save, then come back and re-check. DNS changes can take up to a few hours to show.
All checks
MXCan servers find your inbox?No issues foundPass
Nothing to report.
SPFWho may send as you?SPF is close to the 10-lookup limitNeeds attention
- Warning: SPF is close to the 10-lookup limit
Evaluating the SPF record for hcaptcha.com needs 10 of the 10 allowed DNS lookups. Adding one more service, or a provider growing its own record, will break SPF.
How to fix this - Info: SPF ends in softfail (~all)
"~all" is common and works well with DMARC. "-all" is stricter; switch when you are sure every sender is listed.
DKIMAre your emails signed?DKIM key shorter than 2048 bitsNeeds attention
- Warning: DKIM key shorter than 2048 bits
krs (1024-bit) uses an RSA key below 2048 bits. Short keys can be factored and some receivers treat them as weak. Rotate to a 2048-bit key at your sending provider.
- Pass: DKIM key published
hcaptcha.com publishes a DKIM key under krs.
DMARCWhat happens to fakes?No issues foundPass
Nothing to report.
AlignmentDoes it match your From?SPF alignment depends on a custom Return-PathInfo
- Info: SPF alignment depends on a custom Return-Path
This is a heuristic. Your SPF record only authorizes third-party senders (mailgun.org, _spf.mailgun.org, _spf1.mailgun.org, _spf2.mailgun.org, _spf.eu.mailgun.org, amazonses.com, us-west-2.amazonses.com, mail.zendesk.com, 20974113.spf07.hubspotemail.net). By default they bounce from their own Return-Path domain, and SPF then passes for that domain, not hcaptcha.com. Even relaxed alignment needs the Return-Path's organizational domain to be hcaptcha.com, so set up a custom Return-Path (bounce) domain under hcaptcha.com with each provider, and sign with DKIM as hcaptcha.com.
BIMICan inboxes show your logo?No BIMI recordInfo
- Info: No BIMI record
No BIMI record at default._bimi.hcaptcha.com. BIMI is optional: it shows your logo next to your mail in supporting inboxes once DMARC is enforced.
How to fix this
MTA-STSIs mail to you encrypted?No issues foundPass
Nothing to report.
TLS-RPTWill you hear about failures?TLS-RPT is configuredPass
- Pass: TLS-RPT is configured
TLS reports will be sent to mailto:security@hcaptcha.com.
Other fixes
Prepare BIMIinstruction
BIMI shows your logo next to messages in supporting inboxes, but only for mail that passes DMARC under an enforced policy.
Applies to: default._bimi.hcaptcha.com
- Enforce DMARC first: p=quarantine or p=reject at 100% (no pct below 100). 2. Convert your logo to an SVG Tiny PS file and host it over HTTPS, for example https://hcaptcha.com/bimi/logo.svg. 3. For Gmail and Apple Mail, obtain a VMC or CMC certificate for the logo. 4. Publish a TXT record at default._bimi.hcaptcha.com with v=BIMI1, l= set to the logo URL and a= set to the certificate URL.