Domain Trust Report • Software Development & Code Hosting

github.com Security Audit & Domain Trust Score

Audit github.com developer security, commit notification authenticity, DMARC reject enforcement, and SSL certificate health.

Quick Answer • github.com Security Posture Rating

github.com operated by GitHub, Inc. (Microsoft) maintains an A+ Trust Rating (98/100). The domain enforces strict DMARC policy (p=reject; pct=100), uses 2048-bit RSA DKIM signatures, and is encrypted with TLS 1.3 certificates issued by DigiCert Global Root G2.

Live Security Audit for github.com

Execute a live multi-protocol audit across DNS, SPF, DKIM, DMARC, and TLS handshake sockets.

Live DNS Probe

Security Architecture Overview: github.com

GitHub protects developer accounts and supply chain integrity with strict DMARC p=reject enforcement, neutralizing fake security alerts and compromised OAuth token lures.

Key Anti-Spoofing & Cryptographic Highlights

Supply Chain Phishing Defense: Strict DMARC prevents spoofed security vulnerability notices.
Hardware Security Key (FIDO2) Enforced: Enterprise authentication standard.

Frequently Asked Questions

Does GitHub use DMARC reject?

Yes. GitHub enforces p=reject to protect open-source developers from targeted credential theft.

Why does github.com's SPF include both Google and Mailgun?

GitHub uses both Google Workspace for internal staff email and Mailgun for transactional developer notifications (CI/CD alerts, PR comments, security advisories). Both sending providers are listed in the SPF record to ensure DMARC alignment for all outbound mail streams.

What SSL certificate does github.com use?

GitHub.com uses DigiCert Global Root G2-issued certificates. DigiCert is the dominant CA for high-traffic developer infrastructure. Following Microsoft's acquisition of GitHub, certificate management is tightly integrated with Azure CDN edge nodes.

What is GitHub's supply chain phishing threat model?

Attackers target developers with fake security vulnerability disclosure emails, spoofed Dependabot alerts, or fake 2FA reset requests. Because source code credentials grant access to production systems, developer-targeted phishing is classified as a supply chain attack vector.

How old is github.com?

GitHub.com was registered on October 9, 2007 — over 18 years ago. Despite being younger than most enterprise domains in this audit, its institutional ownership by Microsoft and consistent security posture provide a near-maximum trust score.

Does GitHub enforce FIDO2 hardware key authentication?

Yes. GitHub requires FIDO2 hardware security keys (e.g. YubiKey) for accounts with elevated privileges. This is relevant to email security: even with perfect DMARC, social engineering attacks that trick developers into resetting credentials remain a risk.