Perplexity — security posture
AI answer engine.
C71Last scanned August 27, 2026
Vendor domain: perplexity.ai
Email authentication
- DMARCEnforced (p=reject).
- SPFPublished — authorizes which servers may send mail for this domain.
- DKIMDetected — outgoing mail can be cryptographically verified.
- MTA-STSNot published — inbound mail delivery can be downgraded to plaintext.
- TLS-RPTNot published — no reports if mail delivery or TLS fails.
Disclosures
- security.txtPublishes a security contact (RFC 9116).
- llms.txtNo llms.txt.
AI crawler stance
- GPTBotGPTBot's access is unspecified in robots.txt.
- ClaudeBotClaudeBot's access is unspecified in robots.txt.
- Google-ExtendedGoogle-Extended's access is unspecified in robots.txt.
- PerplexityBotPerplexityBot's access is unspecified in robots.txt.
- CCBotCCBot's access is unspecified in robots.txt.
- meta-externalagentmeta-externalagent's access is unspecified in robots.txt.
What this is — and isn't
These are outside-in observations of public infrastructure — DNS, TLS, and well-known paths. They say nothing about the vendor's code, data handling, or internal controls.