Free tool

Email DNS checker

SPF, DKIM, DMARC and MX for one domain, read from public DNS and graded out of 100. The score only counts the checks that came back — a lookup that failed lowers our confidence, not your grade.

Leave the selector empty and we will try the ones the major providers use.

How to read the report

The four cards are the answer. Each one is a record a mailbox provider looks up before deciding what to do with your message, and each links to the tool that does only that record in full detail, with your domain already filled in.

Under them are the findings, worst first. They are written to be acted on: a finding names the tag, the term or the host that is wrong, and says what a receiver does about it today rather than what the specification says in general.

The order to fix things in

  1. Anything marked broken. A missing SPF record or a revoked DKIM key is affecting mail right now.
  2. SPF's lookup budget, if it is close to ten. It is the failure that arrives without warning, on the day somebody adds a CRM.
  3. DMARC at p=none. Add an rua= address first, read a fortnight of reports, then move to p=quarantine.
  4. The rest. MTA-STS, TLS-RPT and BIMI are what a domain that already passes does next. They are reported here and deliberately not scored.

Why a subdomain is often the right answer

Sending application mail from a subdomain — mail.example.com rather than the domain your staff use — keeps a bulk campaign's reputation away from your invoices and lets you publish a strict policy on one without touching the other. The report reads a subdomain exactly as a receiver would, including the DMARC policy it inherits from the parent.

Questions

What does this check?

SPF, DKIM, DMARC and MX, plus MTA-STS, TLS-RPT and BIMI. Everything is read from public DNS through several resolvers; nothing is sent to your domain and nothing is stored.

Why is the DKIM result a warning when I do have DKIM?

A DKIM key lives at a selector, and there is no record anywhere listing a domain's selectors. Without one we try the selectors the major providers use. If your mail is signed with a private selector, enter it in the second field and the check becomes exact.

What is a good score?

Anything below 100 has something worth fixing, but the grade is not the point — the findings are. A domain with SPF, DKIM and DMARC at p=quarantine or p=reject is protected against forgery, and that is what the report tells you in one line.

The report says my score could not be calculated.

Too few of the four checks came back conclusively — usually a resolver having a bad moment. Nothing is claimed about your domain in that case. Try again in a minute.

How often can I run it?

As often as you like, within a per-address limit that no human reaches. Answers for the same domain are cached for a few minutes, so a re-check right after fixing a record may need a moment to show the change.

Check another record