Email Security Check: SPF, DKIM and DMARC Checker for Any Domain
Enter a domain and this free tool checks its SPF, DKIM, DMARC, MTA-STS, CAA and DNSSEC records, gives it a grade from A to F, and shows the exact record to publish to fix each problem. It reads public DNS from your browser, needs no account, and stores nothing.
- Free
- No signup
- Runs in your browser
- SPF, DKIM, DMARC
- Grade A to F
How it works
- 1Enter a domainType the domain you send email from, such as yourcompany.com.
- 2Public DNS is checkedSPF with lookup counting, 22 DKIM selectors, DMARC, MTA-STS, TLS-RPT, CAA and DNSSEC.
- 3Get a grade and recordsA score out of 100, what lost points, and the exact records to publish.
What the email security check covers
It checks the DNS records that decide whether someone else can send mail that pretends to be your domain, and a few that harden mail delivery.
| Record | What the tool checks |
|---|---|
| SPF | Which servers may send mail for your domain, and what receivers should do with the rest. The tool follows every include and counts DNS lookups against the limit of 10. |
| DKIM | Whether your outgoing mail is signed. DKIM keys live at a selector you choose, so the tool tries 22 common ones and estimates key strength. |
| DMARC | The policy that tells receivers to reject or quarantine spoofed mail, and whether you receive reports. |
| MX | Which mail provider handles your mail, used to give provider-specific advice. |
| MTA-STS and TLS-RPT | Records that force encrypted delivery to your mail servers and report failures. |
| CAA | Which certificate authorities may issue certificates for your domain. |
| DNSSEC | Whether your DNS answers are cryptographically signed and validate. |
How the grade is calculated
The grade is a score out of 100 built from four parts, so you can see exactly where points were lost.
| Part | How it scores | Maximum |
|---|---|---|
| SPF | No record 0. Invalid (several records, over 10 lookups, +all, ?all or no all) 8. Soft fail (~all) 20. Hard fail (-all) 25. | 25 |
| DMARC | No record 0. p=none 10. p=quarantine 30. p=reject 40. Subtract 8 if pct is below 100. Add 3 if reports (rua) are set, up to the maximum. | 40 |
| DKIM | Signing key found with 2048 bits or more, or ed25519: 20. Weak (about 1024-bit) key or test mode: 14. None found on common selectors: 10, because the selector may be custom. | 20 |
| Extras | MTA-STS record 5, TLS-RPT record 3, CAA record 3, DNSSEC validated 4. | 15 |
An A is 90 or more, B is 75 to 89, C is 60 to 74, D is 40 to 59 and F is below 40. A domain that receives no mail and publishes v=spf1 -all with a DMARC policy of reject scores full marks for SPF and DMARC.
How to fix the most common problems
Most domains lose points for the same few reasons, and each has a short fix.
- No DMARC record: publish
v=DMARC1; p=none; rua=mailto:[email protected]at_dmarc.yourdomain.com, read the reports, then move to quarantine and reject. - DMARC stuck at p=none: it only monitors. Fix any legitimate sender that fails, then raise the policy step by step.
- More than 10 SPF lookups: remove unused includes, and avoid listing several services that send the same mail.
- Two SPF records: merge them into one, because a domain may publish only one.
- SPF ending in ?all or +all: change it to ~all or -all.
- DKIM key too short: generate a 2048-bit key in your mail provider and rotate it.
Frequently asked questions
What are SPF, DKIM and DMARC?
SPF lists the servers allowed to send mail for your domain. DKIM adds a cryptographic signature to your mail so receivers can tell it was not altered and came from you. DMARC ties the two together and tells receivers what to do when a message fails, for example reject it, and where to send reports. You need all three to stop others from sending mail that pretends to be you.Why does the tool say it could not find my DKIM key?
A DKIM key lives at a selector chosen by your mail provider, such as selector1 or google, and there is no way to list selectors from outside. The tool tries 22 common ones. If yours is custom it will not be found, which does not mean DKIM is missing. Find the selector in your provider's admin settings or in the headers of a message you sent (look for 's=' in the DKIM-Signature header).What is the difference between ~all and -all in SPF?
-all tells receivers to reject mail from servers that are not listed. ~all tells them to accept it but mark it suspicious. Many domains use ~all and rely on DMARC to enforce the policy, which is acceptable. Once you are sure every legitimate sender is listed, -all is stricter.What is the SPF limit of 10 DNS lookups?
SPF allows at most 10 DNS lookups caused by include, a, mx, ptr, exists and redirect terms, counting the ones inside included records. Over the limit, receivers treat SPF as a permanent error. Each cloud service you add as an include uses lookups, so large domains hit the limit. Remove unused includes or move to a single sending service.How do I move DMARC from p=none to p=reject safely?
Start with p=none and a rua address so you receive reports. Read them for a few weeks and fix any legitimate sender that fails. Then move to p=quarantine with pct=25, raise pct to 100, and finally switch to p=reject. Jumping straight to reject can block your own mail if a sender is missing from SPF or DKIM.I do not send email from this domain. Do I still need these records?
Yes. Attackers spoof parked and unused domains too. Publish v=spf1 -all, a DMARC record with p=reject, and a null MX record if the domain should never receive mail.Does this test email deliverability or spam scores?
No. It checks the DNS records that protect your domain from spoofing. It does not send mail, test inboxes or score content.Is my domain sent to ScanTitan?
No. The lookups run in your browser through Google Public DNS, with Cloudflare DNS as a fallback, so those services see the domain you check. ScanTitan does not receive it.Email is one part of your external exposure. See the rest with a free scan.
Run a free scanSee pricing