Email DNS Checker: test SPF, DMARC, DKIM and MX in one click
Enter a domain and get an email authentication health score out of 100: MX servers, SPF syntax and its 10 DNS-lookup limit, duplicate SPF records, DMARC policy and reports, DKIM keys at common selectors, plus MTA-STS, TLS-RPT and BIMI โ with a plain-English fix list. Lookups go from your browser to public DNS only.
Free ยท No sign-upHow to use Email DNS Checker (SPF, DMARC, DKIM)
- 1. Type a domain (yours or any other) and click Check.
- 2. Read the score out of 100 and the fix list โ the most important problems come first.
- 3. Open each section: MX, SPF (lookups used of the 10 allowed), DMARC (policy and reports), DKIM selectors found, and MTA-STS / TLS-RPT / BIMI.
- 4. Fix the records at your DNS host, then check again. Copy report to share the result with your IT person or host.
Frequently asked questions
What does the email DNS checker test?
MX records and whether the mail servers resolve, SPF (one record only, valid syntax, how it ends, and the DNS-lookup count against the limit of 10), DMARC (valid record, p=none, quarantine or reject, and a reporting address), DKIM keys at common selectors, and the MTA-STS, TLS-RPT and BIMI records.
Why does SPF have a 10 DNS-lookup limit?
RFC 7208 limits the include, a, mx, ptr, exists and redirect terms to 10 DNS lookups per check, nested includes included. Past 10, receivers return a permanent error and SPF fails. The checker follows every include and counts them for you.
Why wasn't my DKIM key found?
DKIM keys live at selector._domainkey.yourdomain and selectors can't be listed from DNS, so the checker tries the common ones (google, selector1, selector2, k1, s1, default, zoho, mail and more). If your provider uses another selector, your DKIM may be fine.
Which DMARC policy should I use?
Start with p=none and a rua reporting address to see who sends mail as your domain. When the reports show your real mail passes SPF or DKIM, move to p=quarantine and then p=reject so spoofed mail is blocked.
Is it safe to check a domain here?
Yes. The lookups go from your browser to Cloudflare's and Google's public DNS-over-HTTPS resolvers, the same answers any mail server sees. Nothing is sent to GrabCast and nothing is stored.
Do I need all of these records?
Every domain that sends mail should have SPF, DKIM and DMARC; Google and Yahoo require them for bulk senders. A domain that never sends mail should publish v=spf1 -all and a DMARC p=reject record. MTA-STS, TLS-RPT and BIMI are optional extras.