Tools › Email
SPF, DKIM & DMARC Checker
Paste a domain's SPF, DKIM or DMARC record to have each part explained and mistakes pointed out: too many lookups, a weak ending, a missing policy, short keys. Give the domain to get the commands that look the records up.
About this tool What it's for, how to use it and an example
What it's for
Understand and check the DNS records that prove a domain’s email is genuine. SPF lists the servers allowed to send a domain’s mail, DKIM publishes the key its messages are signed with, and DMARC tells receivers what to do with mail that fails both and where to send reports. A small mistake in any of them sends real mail to spam or lets forgers through.
For example, when your newsletters start landing in spam after adding a new mailing service, paste your SPF and DMARC records here to check you haven’t gone over SPF’s lookup limit or ended up with two SPF records.
How to use it
Paste one or more records, one a line. Quotes are fine, and so is a line copied from dig or nslookup output:
the quoted parts are joined, as DNS does with long records. Each record is recognised by how it starts (v=spf1,
v=DMARC1, or v=DKIM1 or a p= key) and gets a list of anything wrong, then a table explaining each part.
To get the records, type the domain (and, for DKIM, the selector, which is the s= in a message’s DKIM-Signature
header) and copy a command into a terminal. The commands are only shown: this page doesn’t look anything up. The
checks include SPF’s 10-lookup limit, the strength of its all, DMARC’s policy and report addresses, and the size
of a DKIM key.
Example
Domain example.com, and these records:
"v=spf1 include:_spf.mail.example ip4:192.0.2.0/24 ~all"
"v=DMARC1; p=none; rua=mailto:dmarc@example.com"
The message says 2 records, no errors. The SPF record has notes that it needs 1 DNS lookup here (plus whatever the
include needs) and that ~all marks other senders as suspicious rather than failing them. The DMARC record’s note
says p=none only asks for reports. The commands include dig +short TXT _dmarc.example.com.
Good to know
It checks the text you paste; it can’t follow includes or redirects to count their lookups, or check that a DKIM key matches the signatures. For that, send a message to a mailbox and read its Authentication-Results in the Email Header Analyser. BIMI, MTA-STS and TLS reporting records aren’t checked.
Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.
Saved you a few minutes? Say thanks with a coffee.
Something wrong with this tool, or missing from it? Report a bug or suggest a feature.