webtrajans
en

SPF, DKIM & DMARC Checker

Check a domain’s email authentication — MX, SPF, DKIM, DMARC and BIMI — and get a score with the exact fixes to land in the inbox.

This tool runs entirely in your browser; your data is never sent to a server.

How to use

  1. 1Enter your domain (the part after @ in your email address).
  2. 2We query MX, SPF, DMARC, BIMI and common DKIM selectors via DNS.
  3. 3Review the score and each record’s status.
  4. 4Apply the listed fixes in your DNS, then run the check again.

Why email authentication is now mandatory

Since February 2024, Gmail and Yahoo require bulk senders (5,000+ messages a day to Gmail) to have SPF, DKIM and DMARC in place, and Microsoft applied similar rules to Outlook.com in 2025. Even small senders without them see more mail land in spam or rejected outright. Authentication also stops attackers from spoofing your domain in phishing emails.

SPF: the 10-lookup limit and the all mechanism

SPF is a single TXT record starting with v=spf1 that lists the servers allowed to send for your domain. Each include, a, mx, ptr, exists and redirect costs a DNS lookup, and more than 10 makes SPF fail with a permerror — the most common SPF bug, caused by stacking includes for every email tool you use. Two separate v=spf1 records are also an error; merge them into one. End with ~all (softfail) or -all (fail); ?all is neutral and +all lets anyone send as you, which is worse than having no SPF.

DMARC and DKIM

DKIM signs each message with a private key; the public key lives at <selector>._domainkey.yourdomain. We test common selectors (default, google, selector1, selector2 for Microsoft 365, k1, mail, dkim, s1, s2); if yours uses a different one, we may not find it even though it exists. DMARC, at _dmarc.yourdomain, tells receivers what to do when SPF/DKIM fail: start with p=none and a rua address to collect reports, then move to p=quarantine and finally p=reject once all legitimate sources pass. BIMI, which can show your logo in inboxes, requires DMARC at quarantine or reject.

Frequently asked questions

How do I fix “too many DNS lookups” in SPF?

Remove includes for services you no longer use, replace a and mx mechanisms with ip4/ip6 ranges where practical, or move a sender to a subdomain with its own SPF record.

DKIM shows as missing but I set it up. Why?

Your provider probably uses a selector we don’t test. Find the selector in an email’s DKIM-Signature header (the s= value) and query <selector>._domainkey.yourdomain with our DNS lookup.

Which DMARC policy should I use?

Begin with p=none and monitor reports for a few weeks, then p=quarantine, then p=reject. Jumping straight to reject can block legitimate mail from tools you forgot about.

Should I use ~all or -all?

With DMARC enforcing, ~all is the common, safe choice. -all is stricter; use it once you are sure every legitimate sender is listed.

Not happy with the results?

Talk to Webin Agency about fast, SEO-friendly websites, e-commerce and Google Ads management.

Get free advice

Related tools