Free SPF, DKIM & DMARC lookup

Check your email DNS records in seconds

SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT and BIMI — read live from DNS, graded, and explained with the exact record to publish when something is wrong.

Check records
Know your DKIM selector? No signup · live DNS lookups · results in seconds
7
record types checked
50+
DKIM selectors probed
~3s
typical check
$0
no account needed
What we check

Seven records, and what each one is actually for

Every check is a live DNS query made when you press the button — and every finding tells you what is published, what a receiver will make of it, and what to publish instead.

SPF

A list of the servers allowed to send mail as your domain.

We read your record the way a receiver's parser does: one record only, no +all, and — the failure almost nobody catches — under the hard limit of 10 DNS lookups, counting everything your includes pull in behind them. Past that limit SPF returns a permanent error and fails for every message you send, no matter how correct the record looks.

DKIM

The public key receivers use to verify your signature.

DNS gives no way to list a domain's selectors, so we probe the ones real providers publish — Google, Microsoft 365, Zoho, Amazon SES, Postmark, SendGrid and dozens more — then check that each key actually decodes, is long enough, and has not been revoked or left in testing mode. Know your selector? Enter it and we check that one directly.

DMARC

What receivers should do when SPF and DKIM fail.

We report your policy, whether it is inherited from your organisational domain, whether pct= is quietly applying it to only part of your mail, and whether anyone is actually receiving the aggregate reports. A DMARC record with no rua= is enforcement with the lights off.

MX

Where mail addressed to you is delivered.

We resolve every MX host to make sure it exists, flag a single point of failure, and identify who runs your mail. A domain that only sends still needs somewhere for bounces and replies to go — or an explicit null MX saying it does not.

MTA-STS

Enforced TLS for mail sent to you.

Without it, an attacker on the network path can strip encryption from mail on its way to you and nothing complains. We check both halves — the DNS record and whether the policy host it points at actually resolves, which is where most rollouts quietly stall.

TLS-RPT & BIMI

Reports when TLS fails, and your logo in the inbox.

TLS-RPT costs one record and is the only way you will hear that senders cannot negotiate TLS with your servers. BIMI puts your logo beside your messages — but only once DMARC is at quarantine or reject, which we check before telling you it will work.

How it works

A domain in, a fix list out

No agent to install, no zone file to upload, no account to create.

01

Type your domain

Just the domain — example.com. Paste a full URL or an email address and we will take the domain out of it.

02

We query it live

Every lookup happens when you press the button. Nothing is served from a stale database of what your records looked like last week.

03

Fix what is flagged

Each finding says what is published, what is wrong with it, and the exact record to publish instead — with a copy button.

FAQ

About the DNS checker

No. The DNS checker needs no signup, no email address and sets no cookie. It reads public DNS — the same records anyone can look up with dig — so there is nothing to protect behind a login. Sign-in only matters for the parts of the product that hold your data: saved history, the sandbox inbox and temporary mailboxes.
This checks what is published in DNS. The deliverability test scores a real message you send us, which is the only way to know whether SPF actually passes from your sending IP, whether your DKIM signature verifies, and what SpamAssassin makes of your content. Correct records are necessary and not sufficient — start here, then send a message to be sure.
Because DKIM keys hide behind a selector — an arbitrary name only the sender knows — and DNS offers no way to list them. We probe more than fifty selectors that real providers use, but a custom or randomly generated one is unguessable. Enter your selector in the advanced field and we will check it directly. That is also why the report says "no key answered at the selectors we tried" rather than "you have no DKIM".
DNS answers are cached for the length of each record's TTL, so a change can take anywhere from a few minutes to a few hours to be visible everywhere — including to us. We hold a scan result for about a minute; press Re-check after that and the lookups run again.
It starts at 10 and every problem subtracts from it, weighted by how much that problem actually costs you at a real mailbox provider — a missing DMARC record costs far more than a missing BIMI one, which costs nothing. The report shows every deduction with its reason, so the number is auditable rather than a black box.
We keep a record of which domains were checked and what the result was, so we can see which checks matter and improve them. It is a log of public DNS facts about domains, not of people: no account is created, no cookie is set, and a check cannot be tied back to you unless you were already signed in.
Yes. POST a JSON body of {"domain":"example.com"} to /api/dns/scan and you get the same report this page renders. It is rate-limited per IP for anonymous callers; send an API key as a bearer token to attribute the calls to your account and lift the cap on a paid plan.

Records are the floor, not the ceiling

A clean DNS report means nothing obvious is wrong. To know what a mailbox provider really does with your mail, send it one — free, no account, about fifteen seconds.

Run a free deliverability test