SPF · DKIM · DMARC · MTA-STS
E-mail security checker
Enter a domain or an e-mail address to check whether its mail is protected against spoofing and lands in the inbox. Every record is read live from DNS.
What does the e-mail checker test?
- SPF: which servers may send mail for the domain, how many DNS lookups the record needs (the limit is 10) and how strict its final rule is.
- DKIM: whether a signing key is published for common selectors, and how long it is.
- DMARC: what receivers should do with mail that fails SPF and DKIM, and whether reports are sent to the domain owner.
- MX, MTA-STS, TLS-RPT and BIMI: who receives the mail, whether encrypted delivery is enforced and reported, and whether a brand logo is published.
Frequently asked questions
›Why does my mail go to spam?
Large providers such as Gmail and Outlook require SPF, DKIM and DMARC from bulk senders. A missing record, an SPF record over 10 lookups or a DMARC policy that does not align is the most common cause.
›Is ~all or -all better?
With DMARC in place, ~all is common and safe: DMARC decides what happens. Without DMARC, -all gives stronger protection. +all and ?all give none.
›Why was my DKIM key not found?
DKIM keys live under a selector name that cannot be listed from DNS. We try the selectors of the common providers; if yours is different, enter it in the selector field.
›Does the check store anything?
No. Every check reads DNS live at that moment; the result is not cached or stored.