Assessment Report

hubspot.com  ·  Assessment 6036f7c4-d1f...  ·  2026-06-11T15:29:51

Executive Summary

Infrastructure assessment of hubspot.com identified 4 core issues backed by 17 diagnostic evidence items.

Key Risks

  • Multiple MX IPs on Reputation Blocklists (10 hits)
  • MTA-STS Not Deployed for hubspot.com
  • Multiple DKIM Selectors Below 2048-bit (5 selectors)

Business Impact

  • Potential email deliverability degradation due to blocklist inclusion.
  • Reduced cryptographic assurance and potential verification failures.
  • Increased exposure to mail transport downgrade attacks.

Priority Actions

  • Identify and resolve the root cause of the listing. Submit an official delisting request to Invaluement ivmSIP.
  • 1. Create a TXT record at _mta-sts.{domain}: v=STSv1; id=. 2. Host the policy at https://mta-sts.{domain}/.well-known/mta-sts.txt. 3. Start with mode: testing, then promote to mode: enforce.
  • Rotate to a 2048-bit RSA key during next maintenance window.

Finding Summary

0
CRITICAL
1
HIGH
2
MEDIUM
1
LOW
13
INFORMATIONAL

Root Issues vs Evidence Items

SeverityRoot IssueEvidence Items
HIGHMultiple MX IPs on Reputation Blocklists (10 hits)10
MEDIUMMTA-STS Not Deployed for hubspot.com1
MEDIUMMultiple DKIM Selectors Below 2048-bit (5 selectors)5
LOWTLS-RPT Not Deployed for hubspot.com1

Infrastructure Overview

Mail PlatformsGoogle Workspace
DNS ProvidersCloudflare
ESPsHubSpot

Findings

Multiple MX IPs on Reputation Blocklists (10 hits)

[S] HIGH[C] HIGH[✓] CONFIRMED

MX host IP 74.125.200.26 is listed on Invaluement ivmSIP (sip.invaluement.com). Certain receiving systems consuming this reputation source may reject or filter mail originating from listed infrastructure.

Diagnostic Evidence
Hit 1: 74.125.200.26 on sip.invaluement.com
Hit 2: 74.125.200.26 on sip24.invaluement.com
Hit 3: 74.125.200.27 on sip.invaluement.com
Hit 4: 74.125.200.27 on sip24.invaluement.com
Hit 5: 172.253.118.27 on sip.invaluement.com
Hit 6: 172.253.118.27 on sip24.invaluement.com
Hit 7: 64.233.170.26 on sip.invaluement.com
Hit 8: 64.233.170.26 on sip24.invaluement.com
Hit 9: 64.233.170.27 on sip.invaluement.com
Hit 10: 64.233.170.27 on sip24.invaluement.com

Business Impact: Certain receiving systems may reject or filter messages originating from listed infrastructure. Potential deliverability degradation for receivers consuming this reputation feed.

Remediation: Identify and resolve the root cause of the listing. Submit an official delisting request to Invaluement ivmSIP.

Ref: Threat Intelligence Integration

MTA-STS Not Deployed for hubspot.com

[S] MEDIUM[C] HIGH[✓] CONFIRMED

No MTA-STS TXT record was found. MTA-STS prevents downgrade attacks and STARTTLS stripping on inbound mail delivery.

Diagnostic Evidence
domain: hubspot.com
queried: _mta-sts.hubspot.com
result: NOANSWER
collected_at: 2026-06-11T15:20:18.822178+00:00

Business Impact: Inbound mail is vulnerable to opportunistic TLS downgrade attacks. An attacker with network access can force plaintext delivery.

Remediation: 1. Create a TXT record at _mta-sts.{domain}: v=STSv1; id=. 2. Host the policy at https://mta-sts.{domain}/.well-known/mta-sts.txt. 3. Start with mode: testing, then promote to mode: enforce.

Ref: RFC 8461

Multiple DKIM Selectors Below 2048-bit (5 selectors)

[S] MEDIUM[C] HIGH[✓] CONFIRMED

DKIM selector 'google' uses a 1024-bit RSA key. RFC 8301 recommends a minimum of 2048 bits for new deployments.

Diagnostic Evidence
Selector 1: google (1024-bit)
Selector 2: hs1 (1024-bit)
Selector 3: hs2 (1024-bit)
Selector 4: m1 (1024-bit)
Selector 5: s1 (1024-bit)

Business Impact: The configuration does not align with modern cryptographic recommendations and may become incompatible with future policy requirements.

Remediation: Rotate to a 2048-bit RSA key during next maintenance window.

Ref: RFC 8301

TLS-RPT Not Deployed for hubspot.com

[S] LOW[C] HIGH[✓] CONFIRMED

No TLS-RPT record was found. TLS-RPT enables reporting of TLS negotiation failures from remote MTA connections.

Diagnostic Evidence
domain: hubspot.com
queried: _smtp._tls.hubspot.com
collected_at: 2026-06-11T15:20:18.893623+00:00

Business Impact: TLS delivery failures are not reported and cannot be detected.

Remediation: Add a TXT record at _smtp._tls.{domain}: v=TLSRPTv1; rua=mailto:tls-reports@{domain}

Ref: RFC 8460

Mail Platform Identified: Google Workspace

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

MX record analysis identified Google Workspace as the mail platform for hubspot.com. This establishes the primary mail infrastructure context.

Diagnostic Evidence
vendor: Google Workspace
matched_on: MX
matched_value: smtp.google.com
mx_records: [{'exchange': 'smtp.google.com', 'priority': 1}]
collected_at: 2026-06-11T15:20:14.408284+00:00

Business Impact: Mail platform identification is required to determine expected authentication configuration (DKIM selectors, SPF mechanisms, DMARC policy alignment).

Remediation: No remediation required. This is an infrastructure observation.

DNS Provider Identified: Cloudflare

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

NS record analysis identified Cloudflare as the DNS provider for hubspot.com.

Diagnostic Evidence
vendor: Cloudflare
matched_on: NS
matched_value: jerry.ns.cloudflare.com
ns_records: ['jerry.ns.cloudflare.com', 'yolanda.ns.cloudflare.com']
collected_at: 2026-06-11T15:20:13.841099+00:00

Business Impact: DNS provider identification is relevant to change management, DNS propagation timing, and DNSSEC capability assessment.

Remediation: No remediation required. This is an infrastructure observation.

Email Service Provider Detected: HubSpot

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

HubSpot was identified as an authorised sending platform via SPF include analysis for hubspot.com.

Diagnostic Evidence
vendor: HubSpot
matched_on: SPF_INCLUDE
matched_value: _hspf.hubspot.com
spf_record: v=spf1 redirect=_hspf.hubspot.com
collected_at: 2026-06-11T15:20:17.745149+00:00

Business Impact: Third-party sending platforms affect SPF lookup depth, DKIM alignment, and DMARC pass rates. Each additional sending platform increases infrastructure complexity.

Remediation: No remediation required. This is an infrastructure observation. If this vendor is no longer in use, remove it from SPF to reduce lookup depth.

Tracking/Sending Subdomain Discovered: links.hubspot.com

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

The subdomain links.hubspot.com resolves and is likely used for email tracking, link wrapping, or sending purposes.

Diagnostic Evidence
subdomain: links.hubspot.com
parent_domain: hubspot.com
discovered_via: DNS_CNAME_A_PROBE
collected_at: 2026-06-11T15:20:18.116043+00:00

Business Impact: Tracking subdomains may carry separate sender reputation. Authentication configuration on these subdomains should be consistent with the root domain policy.

Remediation: No remediation required. This is an infrastructure observation. Ensure DMARC subdomain policy is intentionally configured.

Tracking/Sending Subdomain Discovered: track.hubspot.com

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

The subdomain track.hubspot.com resolves and is likely used for email tracking, link wrapping, or sending purposes.

Diagnostic Evidence
subdomain: track.hubspot.com
parent_domain: hubspot.com
discovered_via: DNS_CNAME_A_PROBE
collected_at: 2026-06-11T15:20:18.116043+00:00

Business Impact: Tracking subdomains may carry separate sender reputation. Authentication configuration on these subdomains should be consistent with the root domain policy.

Remediation: No remediation required. This is an infrastructure observation. Ensure DMARC subdomain policy is intentionally configured.

Tracking/Sending Subdomain Discovered: go.hubspot.com

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

The subdomain go.hubspot.com resolves and is likely used for email tracking, link wrapping, or sending purposes.

Diagnostic Evidence
subdomain: go.hubspot.com
parent_domain: hubspot.com
discovered_via: DNS_CNAME_A_PROBE
collected_at: 2026-06-11T15:20:18.116043+00:00

Business Impact: Tracking subdomains may carry separate sender reputation. Authentication configuration on these subdomains should be consistent with the root domain policy.

Remediation: No remediation required. This is an infrastructure observation. Ensure DMARC subdomain policy is intentionally configured.

Tracking/Sending Subdomain Discovered: mail.hubspot.com

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

The subdomain mail.hubspot.com resolves and is likely used for email tracking, link wrapping, or sending purposes.

Diagnostic Evidence
subdomain: mail.hubspot.com
parent_domain: hubspot.com
discovered_via: DNS_CNAME_A_PROBE
collected_at: 2026-06-11T15:20:18.116043+00:00

Business Impact: Tracking subdomains may carry separate sender reputation. Authentication configuration on these subdomains should be consistent with the root domain policy.

Remediation: No remediation required. This is an infrastructure observation. Ensure DMARC subdomain policy is intentionally configured.

DMARC Policy p=reject (Full Enforcement): hubspot.com

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

DMARC policy is p=reject. All unauthenticated mail is rejected.

Diagnostic Evidence
record: v=DMARC1;p=reject;pct=100;rua=mailto:bdlk5ayo@ag.dmarcian.com;ruf=mailto:bdlk5ayo@fr.dmarcian.com
policy: reject
pct: 100

Business Impact: Maximum anti-spoofing protection is in place.

Remediation: No remediation required.

Ref: RFC 7489

DNSSEC Deployed for hubspot.com

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

Both DS and DNSKEY records are present, indicating DNSSEC is deployed.

Diagnostic Evidence
ds_records: [{'key_tag': 2371, 'algorithm': 13, 'digest_type': 2}]
dnskey_records: [{'algorithm': 13}, {'algorithm': 13}]

Business Impact: DNS responses for this domain are cryptographically authenticated.

Remediation: No remediation required.

Ref: RFC 4033

BIMI Deployed for hubspot.com

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

BIMI is deployed. Brand logo will display in supporting mail clients.

Diagnostic Evidence
record: v=BIMI1; l=https://www.hubspot.com/hubfs/hubspot_inc_1435039322.svg; a=https://www.hubspot.com/hubfs/hubspot_inc_1435039322.pem;
logo_url: https://www.hubspot.com/hubfs/hubspot_inc_1435039322.svg
vmc: True

Business Impact: Brand visibility enhanced in BIMI-supporting mail clients.

Remediation: No remediation required.

SPF Lookup Count: 4/10

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

SPF evaluation requires 4 DNS lookups, within the RFC limit.

Diagnostic Evidence
lookup_count: 4
record: v=spf1 redirect=_hspf.hubspot.com

Business Impact: SPF lookup depth is within acceptable limits.

Remediation: No remediation required.

SPF Record Present for hubspot.com

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

A valid SPF record is configured for hubspot.com.

Diagnostic Evidence
record: v=spf1 redirect=_hspf.hubspot.com
lookup_count: 4
all_qualifier: None

Business Impact: Sender authorisation is declared. Authentication analysis can proceed.

Remediation: No remediation required. This is an informational observation.

Ref: RFC 7208

Multiple MX Hosts Passing FCrDNS (5 hosts)

[S] INFORMATIONAL[C] HIGH[O] OBSERVED

Reverse DNS for 64.233.170.26 resolves to sg-in-f26.1e100.net and forward-confirms.

Diagnostic Evidence
Host 1: 64.233.170.26 -> sg-in-f26.1e100.net
Host 2: 64.233.170.27 -> sg-in-f27.1e100.net
Host 3: 172.253.118.27 -> sl-in-f27.1e100.net
Host 4: 74.125.200.27 -> sa-in-f27.1e100.net
Host 5: 74.125.200.26 -> sa-in-f26.1e100.net

Business Impact: FCrDNS passes. Basic PTR reputation check satisfied.

Remediation: No remediation required.

Investigation Roadmap

1. HIGH PRIORITY — Address 1 HIGH finding(s): Multiple MX IPs on Reputation Blocklists (10 hits)
2. MEDIUM PRIORITY — Review 2 MEDIUM finding(s): MTA-STS Not Deployed for hubspot.com, Multiple DKIM Selectors Below 2048-bit (5 selectors)
3. Schedule a verification assessment after remediation to confirm all changes are effective.

Business Impact Summary

CategoryLevel
SECURITYHIGH
DELIVERABILITYMEDIUM
OPERATIONALHIGH
BUSINESS_CONTINUITYMEDIUM