InboxAudit

Mimecast email authentication

Email security gateway that relays outbound mail for enterprises.

Mimecast publishes region-specific includes; check which grid your tenant is on.

SPF record

Add Mimecast to your domain's SPF record with this include:

include:_netblocks.mimecast.com

A complete record for a domain sending only through Mimecast:

v=spf1 include:_netblocks.mimecast.com ~all

What it costs you

8 of your 10 DNS lookups. The include: itself costs one, and Mimecast's record chains to 7 more. Behind it are 68 IP ranges.

At 8 lookups this is an expensive include. If your record is near the limit, this is one of the first places to look — see too many DNS lookups.

Live record

This is what _netblocks.mimecast.com published when this page was generated:

v=spf1 include:eu._netblocks.mimecast.com include:us._netblocks.mimecast.com include:za._netblocks.mimecast.com include:de._netblocks.mimecast.com include:au._netblocks.mimecast.com include:ca._netblocks.mimecast.com include:usb._netblocks.mimecast.com ~all

DKIM

Enable DKIM inside Mimecast and publish the selector record it generates. DKIM matters more than SPF for deliverability, because a DKIM signature survives forwarding while SPF does not — see how selectors work.

DMARC

Neither SPF nor DKIM protects the address your recipients actually see until DMARC ties them to it. Once Mimecast is authenticating, publish a DMARC record — start at p=none with a reporting address and tighten from there.

Generate a DMARC record →

Check it worked

DNS changes take minutes to hours to propagate. Once published, run the domain through the checker — it resolves the full include chain and reports the real lookup count.