homedepot.com

homedepot.com · Last checked 2026-10-04 02:16 UTC

homedepot.com

Excellent, with 1 thing to fix

homedepot.com scored 92/100 (grade A). The main issue is DKIM key shorter than 2048 bits. Detected senders: Microsoft 365 and Zendesk.

Checked 2026-10-04 02:16 UTC · fresh check

2 passed1 needs attention0 failing5 for informationDetected senders: Microsoft 365, Zendesk

All checks

MXCan servers find your inbox?No issues foundPass

Nothing to report.

SPFWho may send as you?SPF ends in softfail (~all)Info
  • Info: SPF ends in softfail (~all)

    "~all" is common and works well with DMARC. "-all" is stricter; switch when you are sure every sender is listed.

DKIMAre your emails signed?DKIM key shorter than 2048 bitsNeeds attention
  • Warning: DKIM key shorter than 2048 bits

    selector1 (1024-bit), k1 (1024-bit) uses an RSA key below 2048 bits. Short keys can be factored and some receivers treat them as weak. Rotate to a 2048-bit key at your sending provider.

  • Pass: DKIM key published

    homedepot.com publishes a DKIM key under selector1, k1, k2, k3.

DMARCWhat happens to fakes?No issues foundPass

Nothing to report.

AlignmentDoes it match your From?SPF alignment depends on a custom Return-PathInfo
  • Info: SPF alignment depends on a custom Return-Path

    This is a heuristic. Your SPF record only authorizes third-party senders (mail.zendesk.com). By default they bounce from their own Return-Path domain, and SPF then passes for that domain, not homedepot.com. Even relaxed alignment needs the Return-Path's organizational domain to be homedepot.com, so set up a custom Return-Path (bounce) domain under homedepot.com with each provider, and sign with DKIM as homedepot.com.

BIMICan inboxes show your logo?No BIMI recordInfo
  • Info: No BIMI record

    No BIMI record at default._bimi.homedepot.com. BIMI is optional: it shows your logo next to your mail in supporting inboxes once DMARC is enforced.

    How to fix this
MTA-STSIs mail to you encrypted?No MTA-STS recordInfo
  • Info: No MTA-STS record

    No MTA-STS record at _mta-sts.homedepot.com. MTA-STS (RFC 8461) makes sending servers require TLS and a valid certificate when delivering to you, which blocks downgrade attacks.

    How to fix this
TLS-RPTWill you hear about failures?No TLS-RPT recordInfo
  • Info: No TLS-RPT record

    No TLS reporting record at _smtp._tls.homedepot.com. TLS-RPT (RFC 8460) tells senders where to send daily reports about failed encrypted deliveries to you.

    How to fix this

How to fix it

Publish the MTA-STS recordTXT

Tells sending servers that homedepot.com publishes an MTA-STS policy at https://mta-sts.homedepot.com/.well-known/mta-sts.txt. Change the id whenever the policy file changes.

TypeTXT
Name / Host
_mta-sts.homedepot.com

Some DNS providers want just “_mta-sts” here.

Value
v=STSv1; id=202610040216

Host the MTA-STS policy filepolicy-file

Serve this file over HTTPS with a valid certificate for mta-sts.homedepot.com. It lists your MX hosts and starts in testing mode; switch to mode: enforce once TLS-RPT reports show no failures.

Location
https://mta-sts.homedepot.com/.well-known/mta-sts.txt
Contents
version: STSv1
mode: testing
mx: mxa-000e6608.gslb.pphosted.com
mx: mxb-000e6608.gslb.pphosted.com
mx: mx0a-000e6608.pphosted.com
mx: mx0b-000e6608.pphosted.com
mx: exchanger1.homedepot.com
mx: exchanger2.homedepot.com
max_age: 604800

Set up a TLS report addressinstruction

Sending servers will report TLS failures when delivering to homedepot.com, which you need before enforcing MTA-STS. The address must accept TLS reports; a DMARC report address does not necessarily do so.

Applies to: _smtp._tls.homedepot.com

  1. Pick an address that will receive TLS reports: a mailbox you read (for example tls-reports@homedepot.com, created first) or a TLS reporting service. 2. Publish a TXT record at _smtp._tls.homedepot.com with the value v=TLSRPTv1; rua=mailto:<that address>.

Prepare BIMIinstruction

BIMI shows your logo next to messages in supporting inboxes, but only for mail that passes DMARC under an enforced policy.

Applies to: default._bimi.homedepot.com

  1. Enforce DMARC first: p=quarantine or p=reject at 100% (no pct below 100). 2. Convert your logo to an SVG Tiny PS file and host it over HTTPS, for example https://homedepot.com/bimi/logo.svg. 3. For Gmail and Apple Mail, obtain a VMC or CMC certificate for the logo. 4. Publish a TXT record at default._bimi.homedepot.com with v=BIMI1, l= set to the logo URL and a= set to the certificate URL.