Free tool
SPF, DKIM, DMARC and MX for one domain, read from public DNS and graded out of 100. The score only counts the checks that came back — a lookup that failed lowers our confidence, not your grade.
The four cards are the answer. Each one is a record a mailbox provider looks up before deciding what to do with your message, and each links to the tool that does only that record in full detail, with your domain already filled in.
Under them are the findings, worst first. They are written to be acted on: a finding names the tag, the term or the host that is wrong, and says what a receiver does about it today rather than what the specification says in general.
p=none. Add an rua= address first, read a fortnight of reports, then move to p=quarantine. Sending application mail from a subdomain — mail.example.com rather than the domain your staff use — keeps a bulk campaign's reputation away from your invoices and lets you publish a strict policy on one without touching the other. The report reads a subdomain exactly as a receiver would, including the DMARC policy it inherits from the parent.
SPF, DKIM, DMARC and MX, plus MTA-STS, TLS-RPT and BIMI. Everything is read from public DNS through several resolvers; nothing is sent to your domain and nothing is stored.
A DKIM key lives at a selector, and there is no record anywhere listing a domain's selectors. Without one we try the selectors the major providers use. If your mail is signed with a private selector, enter it in the second field and the check becomes exact.
Anything below 100 has something worth fixing, but the grade is not the point — the findings are. A domain with SPF, DKIM and DMARC at p=quarantine or p=reject is protected against forgery, and that is what the report tells you in one line.
Too few of the four checks came back conclusively — usually a resolver having a bad moment. Nothing is claimed about your domain in that case. Try again in a minute.
As often as you like, within a per-address limit that no human reaches. Answers for the same domain are cached for a few minutes, so a re-check right after fixing a record may need a moment to show the change.