InboxAudit

Intercom email authentication

In-app messaging and support platform.

This provider does not publish a shared SPF include for customers. It authenticates each account separately, using CNAME records that its own dashboard generates for your domain.

That is a deliberate design and a good one: the records are unique to you, they do not consume any of your ten SPF lookups, and DKIM signing comes with them. Adding a guessed include: for this provider would cost you a lookup and authenticate nothing.

DKIM

Enable DKIM inside Intercom and publish the selector record it generates. DKIM matters more than SPF for deliverability, because a DKIM signature survives forwarding while SPF does not — see how selectors work.

DMARC

Neither SPF nor DKIM protects the address your recipients actually see until DMARC ties them to it. Once Intercom is authenticating, publish a DMARC record — start at p=none with a reporting address and tighten from there.

Generate a DMARC record →

Check it worked

DNS changes take minutes to hours to propagate. Once published, run the domain through the checker — it resolves the full include chain and reports the real lookup count.