SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT and BIMI — read live from DNS, graded, and explained with the exact record to publish when something is wrong.
Every check is a live DNS query made when you press the button — and every finding tells you what is published, what a receiver will make of it, and what to publish instead.
A list of the servers allowed to send mail as your domain.
We read your record the way a receiver's parser does: one record only, no +all, and — the failure almost nobody catches — under the hard limit of 10 DNS lookups, counting everything your includes pull in behind them. Past that limit SPF returns a permanent error and fails for every message you send, no matter how correct the record looks.
The public key receivers use to verify your signature.
DNS gives no way to list a domain's selectors, so we probe the ones real providers publish — Google, Microsoft 365, Zoho, Amazon SES, Postmark, SendGrid and dozens more — then check that each key actually decodes, is long enough, and has not been revoked or left in testing mode. Know your selector? Enter it and we check that one directly.
What receivers should do when SPF and DKIM fail.
We report your policy, whether it is inherited from your organisational domain, whether pct= is quietly applying it to only part of your mail, and whether anyone is actually receiving the aggregate reports. A DMARC record with no rua= is enforcement with the lights off.
Where mail addressed to you is delivered.
We resolve every MX host to make sure it exists, flag a single point of failure, and identify who runs your mail. A domain that only sends still needs somewhere for bounces and replies to go — or an explicit null MX saying it does not.
Enforced TLS for mail sent to you.
Without it, an attacker on the network path can strip encryption from mail on its way to you and nothing complains. We check both halves — the DNS record and whether the policy host it points at actually resolves, which is where most rollouts quietly stall.
Reports when TLS fails, and your logo in the inbox.
TLS-RPT costs one record and is the only way you will hear that senders cannot negotiate TLS with your servers. BIMI puts your logo beside your messages — but only once DMARC is at quarantine or reject, which we check before telling you it will work.
No agent to install, no zone file to upload, no account to create.
Just the domain — example.com. Paste a full URL or an email address and we will take the domain out of it.
Every lookup happens when you press the button. Nothing is served from a stale database of what your records looked like last week.
Each finding says what is published, what is wrong with it, and the exact record to publish instead — with a copy button.
A clean DNS report means nothing obvious is wrong. To know what a mailbox provider really does with your mail, send it one — free, no account, about fifteen seconds.
Run a free deliverability test