mercadolibre.com.ar
Good, with 3 things to fix
mercadolibre.com.ar scored 76/100 (grade B). The main issues are DKIM key shorter than 2048 bits and external DMARC report address is not authorized, plus 1 more. Detected senders: Google Workspace and Zendesk.
Checked 2026-10-04 02:20 UTC · fresh check
Reduce SPF DNS lookups
Evaluating SPF for mercadolibre.com.ar takes 8 DNS lookups including nested includes; receivers stop at 10 and fail SPF. No detected sending service accounts for these includes; remove each one you no longer send through: spfa.mercadolibre.com.ar. Changes: Added include:_spf.google.com for Google Workspace. Added include:mail.zendesk.com for Zendesk. Replaced ~all with -all so mail from servers not listed is rejected.
mercadolibre.com.ar
Some DNS providers want “@” here instead of the full domain.
v=spf1 exists:%{i}._spf.mta.salesforce.com include:spfa.mercadolibre.com.ar ip4:172.217.128.0/19 ip4:172.217.160.0/20 ip4:172.217.192.0/19 ip4:18.211.176.124 ip4:184.73.44.157 ip4:35.190.247.0/24 ip4:64.233.160.0/19 include:_spf.google.com include:mail.zendesk.com -allv=spf1 exists:%{i}._spf.mta.salesforce.com include:spfa.mercadolibre.com.ar ip4:172.217.128.0/19 ip4:172.217.160.0/20 ip4:172.217.192.0/19 ip4:18.211.176.124 ip4:184.73.44.157 ip4:35.190.247.0/24 ip4:64.233.160.0/19 ~allHow to apply it
- Sign in where your domain’s DNS is managed. This is often where you bought the domain, such as Cloudflare, GoDaddy or Namecheap.
- Find the existing TXT record with that name and replace its value.
- Save, then come back and re-check. DNS changes can take up to a few hours to show.
All checks
MXCan servers find your inbox?No issues foundPass
Nothing to report.
SPFWho may send as you?SPF is close to the 10-lookup limitNeeds attention
- Warning: SPF is close to the 10-lookup limit
Evaluating the SPF record for mercadolibre.com.ar needs 8 of the 10 allowed DNS lookups. Adding one more service, or a provider growing its own record, will break SPF.
How to fix this - Info: SPF ends in softfail (~all)
"~all" is common and works well with DMARC. "-all" is stricter; switch when you are sure every sender is listed.
DKIMAre your emails signed?DKIM key shorter than 2048 bitsNeeds attention
- Warning: DKIM key shorter than 2048 bits
google (1024-bit), s2 (1024-bit) uses an RSA key below 2048 bits. Short keys can be factored and some receivers treat them as weak. Rotate to a 2048-bit key at your sending provider.
- Pass: DKIM key published
mercadolibre.com.ar publishes a DKIM key under google, s1, s2.
DMARCWhat happens to fakes?External DMARC report address is not authorizedNeeds attention
- Warning: External DMARC report address is not authorized
Reports go to mercadolibre.com, which is outside mercadolibre.com.ar. RFC 7489 requires that domain to publish a valid v=DMARC1 TXT record at mercadolibre.com.ar._report._dmarc.mercadolibre.com; without it receivers will not send you aggregate reports. Your report provider normally publishes this for you.
- Info: DMARC uses strict alignment
With adkim=s or aspf=s the DKIM d= domain or the bounce domain must equal the From domain exactly; a subdomain is not enough. Third-party senders that sign or bounce from a subdomain (or their own domain) will then fail DMARC unless they are configured to use your exact domain.
AlignmentDoes it match your From?SPF alignment depends on a custom Return-PathInfo
- Info: SPF alignment depends on a custom Return-Path
This is a heuristic. Your SPF record only authorizes third-party senders (mail.zendesk.com). By default they bounce from their own Return-Path domain, and SPF then passes for that domain, not mercadolibre.com.ar. Even relaxed alignment needs the Return-Path's organizational domain to be mercadolibre.com.ar, so set up a custom Return-Path (bounce) domain under mercadolibre.com.ar with each provider, and sign with DKIM as mercadolibre.com.ar.
BIMICan inboxes show your logo?No issues foundPass
Nothing to report.
MTA-STSIs mail to you encrypted?No MTA-STS recordInfo
- Info: No MTA-STS record
No MTA-STS record at _mta-sts.mercadolibre.com.ar. MTA-STS (RFC 8461) makes sending servers require TLS and a valid certificate when delivering to you, which blocks downgrade attacks.
How to fix this
TLS-RPTWill you hear about failures?No TLS-RPT recordInfo
- Info: No TLS-RPT record
No TLS reporting record at _smtp._tls.mercadolibre.com.ar. TLS-RPT (RFC 8460) tells senders where to send daily reports about failed encrypted deliveries to you.
How to fix this
Other fixes
Publish the MTA-STS recordTXT
Tells sending servers that mercadolibre.com.ar publishes an MTA-STS policy at https://mta-sts.mercadolibre.com.ar/.well-known/mta-sts.txt. Change the id whenever the policy file changes.
_mta-sts.mercadolibre.com.ar
Some DNS providers want just “_mta-sts” here.
v=STSv1; id=202610040220
Host the MTA-STS policy filepolicy-file
Serve this file over HTTPS with a valid certificate for mta-sts.mercadolibre.com.ar. It lists your MX hosts and starts in testing mode; switch to mode: enforce once TLS-RPT reports show no failures.
https://mta-sts.mercadolibre.com.ar/.well-known/mta-sts.txt
version: STSv1 mode: testing mx: aspmx.l.google.com mx: alt1.aspmx.l.google.com mx: alt2.aspmx.l.google.com mx: aspmx2.googlemail.com mx: aspmx3.googlemail.com max_age: 604800
Set up a TLS report addressinstruction
Sending servers will report TLS failures when delivering to mercadolibre.com.ar, which you need before enforcing MTA-STS. The address must accept TLS reports; a DMARC report address does not necessarily do so.
Applies to: _smtp._tls.mercadolibre.com.ar
- Pick an address that will receive TLS reports: a mailbox you read (for example tls-reports@mercadolibre.com.ar, created first) or a TLS reporting service. 2. Publish a TXT record at _smtp._tls.mercadolibre.com.ar with the value v=TLSRPTv1; rua=mailto:<that address>.