Free tool
SPF, DKIM and DMARC checker
Enter a domain to see its email authentication records, what's wrong and how to fix it. Free, no sign-up.
What the checker looks at
Four records every sending domain needs.
SPF
Lists the servers allowed to send email for your domain. One TXT record on the domain, ending in ~all or -all.
DKIM
Signs every email so receivers can tell it came from you and wasn't changed. Your email provider gives you the key.
DMARC
Tells receivers what to do when SPF and DKIM fail, and sends you reports. Start with p=none, then tighten.
MX
Where email to your domain is delivered. Without it, replies to your outreach bounce.
New to these records? Read SPF, DKIM and DMARC for cold email or the step-by-step setup guide.
FAQ
- How is each record rated?
- SPF passes when there is exactly one record ending in ~all or -all that needs 10 DNS lookups or fewer. DMARC passes with p=quarantine or p=reject; p=none needs work. DKIM passes when a key is found. MX passes when the domain has at least one mail server.
- Why does DKIM say missing when I've set it up?
- DKIM keys live at a name only your provider knows — the selector. We try the common ones (Google, Microsoft, Mailchimp, SendGrid and more). If yours is different, enter it under Advanced.
- Is this a full deliverability test?
- No. It reads public DNS records only. It can't see whether your emails are actually signed, your sending reputation or blocklists.
- Do you store the domains I check?
- Results are kept in memory for a few minutes so a refresh is instant, then dropped. Checks aren't linked to you or kept as a history; our server logs note which domains were checked, to spot abuse.