Read from stripe.com's public DNS records, the same ones anyone can look up. Nothing was sent and nothing was stored.
stripe.com tells receiving servers to reject anything that fails authentication. This is the correct setting, and most domains never reach it.
This domain accepts email, so it is worth impersonating. Domains that never send are less attractive targets.
aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.comUnlisted senders are marked suspicious but still delivered. This is the common default and it stops very little on its own.
v=spf1 ip4:198.2.180.60/32 ip4:13.111.2.227/32 include:spf1.stripe.com include:greenhouse-outbound-mail.stripe.com include:_spf.qualtrics.com ~allYour outgoing mail is cryptographically signed, so a receiving server can verify it genuinely came from you.
Forged mail claiming to be you is refused at the door. This is the setting you want.
v=DMARC1; p=reject; pct=100; fo=1; rua=mailto:dmarc-reports@stripe.com; ruf=mailto:dmarc-forensics@stripe.com;stripe.com is in good shape today. Records get edited, vendors get added and keys get rotated, so if this stops being true we will email you once.
One email when something changes, and nothing else. Unsubscribe in one click, no account.
Spoofing is one direction of the problem. The other is the inbox itself: reading what came in, deciding the few things that need you, drafting the replies. That is the part Mailient does, on your existing Gmail.
Start free