InboxAudit

Atlassian (Jira & Confluence) email authentication

Notification mail from Jira, Confluence and Jira Service Management.

SPF record

Add Atlassian (Jira & Confluence) to your domain's SPF record with this include:

include:_spf.atlassian.net

A complete record for a domain sending only through Atlassian (Jira & Confluence):

v=spf1 include:_spf.atlassian.net ~all

What it costs you

2 of your 10 DNS lookups. The include: itself costs one, and Atlassian (Jira & Confluence)'s record chains to 1 more. Behind it are 14 IP ranges.

Live record

This is what _spf.atlassian.net published when this page was generated:

v=spf1 ip4:167.89.0.0/17 ip4:168.245.0.0/17 include:amazonses.com -all

Domains using Atlassian (Jira & Confluence)

Found while resolving 293 well-known domains on 2026-08-04 — each authorises _spf.atlassian.net in its published SPF record:

DKIM

Enable DKIM inside Atlassian (Jira & Confluence) and publish the selector record it generates. DKIM matters more than SPF for deliverability, because a DKIM signature survives forwarding while SPF does not — see how selectors work.

DMARC

Neither SPF nor DKIM protects the address your recipients actually see until DMARC ties them to it. Once Atlassian (Jira & Confluence) is authenticating, publish a DMARC record — start at p=none with a reporting address and tighten from there.

Generate a DMARC record →

Check it worked

DNS changes take minutes to hours to propagate. Once published, run the domain through the checker — it resolves the full include chain and reports the real lookup count.

Official documentation

Atlassian (Jira & Confluence) setup docs →