thoughtasylumTOOLBOX Preview

Tools › Email

SPF, DKIM & DMARC Checker

Paste a domain's SPF, DKIM or DMARC record to have each part explained and mistakes pointed out: too many lookups, a weak ending, a missing policy, short keys. Give the domain to get the commands that look the records up.

About this tool What it's for, how to use it and an example

What it's for

Understand and check the DNS records that prove a domain’s email is genuine. SPF lists the servers allowed to send a domain’s mail, DKIM publishes the key its messages are signed with, and DMARC tells receivers what to do with mail that fails both and where to send reports. A small mistake in any of them sends real mail to spam or lets forgers through.

For example, when your newsletters start landing in spam after adding a new mailing service, paste your SPF and DMARC records here to check you haven’t gone over SPF’s lookup limit or ended up with two SPF records.

How to use it

Paste one or more records, one a line. Quotes are fine, and so is a line copied from dig or nslookup output: the quoted parts are joined, as DNS does with long records. Each record is recognised by how it starts (v=spf1, v=DMARC1, or v=DKIM1 or a p= key) and gets a list of anything wrong, then a table explaining each part.

To get the records, type the domain (and, for DKIM, the selector, which is the s= in a message’s DKIM-Signature header) and copy a command into a terminal. The commands are only shown: this page doesn’t look anything up. The checks include SPF’s 10-lookup limit, the strength of its all, DMARC’s policy and report addresses, and the size of a DKIM key.

Example

Domain example.com, and these records:

"v=spf1 include:_spf.mail.example ip4:192.0.2.0/24 ~all"
"v=DMARC1; p=none; rua=mailto:dmarc@example.com"

The message says 2 records, no errors. The SPF record has notes that it needs 1 DNS lookup here (plus whatever the include needs) and that ~all marks other senders as suspicious rather than failing them. The DMARC record’s note says p=none only asks for reports. The commands include dig +short TXT _dmarc.example.com.

Good to know

It checks the text you paste; it can’t follow includes or redirects to count their lookups, or check that a DKIM key matches the signatures. For that, send a message to a mailbox and read its Authentication-Results in the Email Header Analyser. BIMI, MTA-STS and TLS reporting records aren’t checked.

Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

Saved you a few minutes? Say thanks with a coffee.

Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

↑ ↓ move↵ openesc close