Observed Signal · May 20, 2026 · Technical Release · Source: DEV Community · Impact: 3/5 · Sentiment: Negative

26 of 39 AI Firms Use SPF Softfail — Emails Spoofable

Executive Signal Summary

A DNS-based security analysis of 39 AI organizations found that 26 use SPF softfail (~all), meaning unauthorized senders may be accepted and only flagged, while 10 use SPF hardfail (-all) and 3 have no SPF records. The author also audited DMARC policies and found 9 of 39 domains have weak or absent DMARC (p=none or none at all). Examples: major firms such as Anthropic, Google, Apple, NVIDIA and Hugging Face appear among softfail domains; OpenAI, Microsoft and Amazon use hardfail with strict DMARC; Meta, Tesla and Alignment Forum lack SPF. The report highlights risky combinations (e.g., Cohere uses many third‑party senders while retaining ~all) and links to an interactive email security checker (domainintel.vercel.app). Data collection date: 2026-05-20.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Widespread weak SPF/DMARC configurations among prominent AI companies increase phishing and impersonation risk, which affects brand trust, security posture, and email-based communications used by marketing and corporate teams.

SIGNAL RADAR

Track Anthropic Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • 26 of 39 audited AI companies publish SPF records ending in ~all (softfail).
  • 10 of 39 use SPF -all (hardfail); 3 of 39 have no SPF record at all.
  • 9 of 39 domains have weak or absent DMARC (monitoring p=none or no DMARC).
  • Cohere, Jasper, Weaviate and Scale AI highlighted as risky sender configurations; OpenAI and Microsoft cited as having strict enforcement.
  • All findings are derived from public DNS records and were collected on 2026-05-20.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: May 20, 2026
Original Coverage Title: “26 of 39 AI Companies Use SPF Softfail — Their Email Can Be Spoofed”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Email & NewsletterJul 26, 2026

MCP Spec Imminent; Email Authentication Is Weakening

The author scanned 671,693 domains (Tranco forward-DNS snapshot 2026-07-25) and reports widespread weaknesses in email authentication as the MCP spec is about to land. Key findings: 634,220 domains publish SPF, 468,749 publish DMARC, but DMARC enforcement fell by 0.42 percentage points last month despite 9,173 net new DMARC domains; a large share of those records are non-enforcing `p=none` or inert (no working `rua=`). Enforcement correlates with prominence: top-1k sites are far more protected than the long tail. Self-hosted MX is the single largest inbound category (22.79%), exceeding Google Workspace and Microsoft 365. The author warns agentic email products amplify risk through concentrated volume, unaudited SPF includes, and missing telemetry, and gives concrete diagnostic commands and remediation steps.

Read assessment
Email & NewsletterJul 14, 2026

SPF, DKIM and DMARC Determine Inbox Placement

A technical guide explaining how SPF, DKIM and DMARC each play distinct roles in email deliverability for self-hosted mail systems. SPF lists authorized sending IPs in DNS, DKIM cryptographically signs messages and survives normal forwarding, and DMARC enforces alignment between those signals and the visible From address while providing reporting. The author describes common pitfalls (e.g., incorrect DKIM DNS entries), the need to warm new IPs and domains slowly, and operational practices—processing bounces, setting up feedback loops, and keeping lists clean—that matter more than copy for inbox placement. The post notes the author's commercial product AcelleMail but states the guidance is product-agnostic.

Read assessment
Email & NewsletterMay 30, 2026

30-Point Domain Security Audit Explained

The article describes a structured 30-point security audit for internet domains that systematically checks DNS, email, infrastructure, compliance mapping, and expiry controls. The audit groups checks into five categories: Email Security (8 checks), DNS Security (10), Infrastructure Security (6), Compliance Mapping (4), and Additional Checks (2). Each check yields pass/fail/warning results, produces a fix guide for failures, and contributes to an aggregate Email Health Score (0–100); most domains score 40–65 on a first run. High-severity risks highlighted include subdomain takeover, open zone transfers, blacklist listings, and DMARC configured with p=none. The article maps technical findings to regulatory frameworks (NIS2, GDPR, ISO 27001, PCI-DSS) and notes a publicly accessible implementation at zerohook.org, with a free tier covering core email checks and paid plans (full audit) starting at $49/month. Publication date: 2026-05-30.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.