pushy.io
Poor, with 6 things to fix
pushy.io scored 58/100 (grade D). The main issues are no SPF record and no DKIM key found for the common selectors, plus 6 more. Detected senders: Mailgun.
Checked 2026-10-04 02:14 UTC · fresh check
Diagnosis notes
- Warning: DNS lookup budget exhausted
This diagnosis stopped sending DNS queries after 8000 ms. Checks that needed more lookups report their remaining results as unknown; the domain's records may be unusually large or slow to answer.
Publish an SPF record
Lists the sending services detected for pushy.io (Mailgun) and rejects everything else. Add any other service that sends as pushy.io before publishing. Changes: Added include:mailgun.org for Mailgun.
pushy.io
Some DNS providers want “@” here instead of the full domain.
v=spf1 include:mailgun.org -all
How to apply it
- Sign in where your domain’s DNS is managed. This is often where you bought the domain, such as Cloudflare, GoDaddy or Namecheap.
- Add a new TXT record with the name and value above.
- Save, then come back and re-check. DNS changes can take up to a few hours to show.
All checks
MXCan servers find your inbox?No issues foundPass
Nothing to report.
SPFWho may send as you?No SPF recordFailing
- Fail: No SPF record
pushy.io publishes no TXT record starting with "v=spf1", so receivers cannot tell which servers may send mail for it. Publish one SPF record listing every service that sends as pushy.io.
How to fix this
DKIMAre your emails signed?No DKIM key found for the common selectorsNeeds attention
- Warning: No DKIM key found for the common selectors
None of the 47 selectors probed under pushy.io publish a DKIM key. DNS cannot list selectors, so a key under a custom selector may exist: find the s= value in the DKIM-Signature header of a message you sent and check that selector. If DKIM is not set up, enable it at each service that sends mail for pushy.io.
- Warning: Some DKIM lookups failed
39 of 47 selector lookups under pushy.io returned TIMEOUT, so whether those selectors hold a key is unknown. Try again later; if it persists, check the domain's nameservers.
DMARCWhat happens to fakes?Could not look up the DMARC recordNeeds attention
- Warning: Could not look up the DMARC record
The DNS query for _dmarc.pushy.io returned TIMEOUT. The DMARC result is unknown; try again later.
AlignmentDoes it match your From?Alignment could not be fully assessedInfo
- Info: Alignment could not be fully assessed
Alignment could not be judged because of the DMARC lookup failed. The affected verdicts are reported as unknown rather than guessed.
BIMICan inboxes show your logo?Could not look up the BIMI recordNeeds attention
- Warning: Could not look up the BIMI record
The TXT query for default._bimi.pushy.io returned TIMEOUT, so BIMI status is unknown. Try again later.
MTA-STSIs mail to you encrypted?Could not look up the MTA-STS recordNeeds attention
- Warning: Could not look up the MTA-STS record
The TXT query for _mta-sts.pushy.io returned TIMEOUT, so MTA-STS status is unknown. Try again later.
TLS-RPTWill you hear about failures?Could not look up the TLS-RPT recordNeeds attention
- Warning: Could not look up the TLS-RPT record
The TXT query for _smtp._tls.pushy.io returned TIMEOUT, so TLS-RPT status is unknown. Try again later.
Other fixes
Enable DKIM for Mailguninstruction
Mailgun generates the DKIM key for each account, so the exact record must come from Mailgun. Without DKIM, mail it sends for pushy.io cannot pass DMARC through DKIM.
Applies to: mg._domainkey.pushy.io
- In Mailgun, enable DKIM signing for pushy.io: account-specific: copy the CNAME/TXT from the Mailgun dashboard. Publish exactly the record Mailgun shows (TXT or CNAME) at the host name it gives, then turn signing on. Instructions: https://documentation.mailgun.com/docs/mailgun/user-manual/domains/domains-verify