Tools · Email domain

EMAIL DOMAIN SECURITY

A check of SPF, DMARC and DKIM from public DNS. It shows whether fraudulent mail can be sent in the name of your domain and how strict the current rules are.

Enter a domain and the tool reads the records from public DNS that receiving servers use to decide whether a message carrying your address is genuine. Each section explains what it means and what to do about the finding.

The check sends nothing and connects to nothing except DNS. You can run it on someone else's domain — it is the same information every mail server in the world has about it. The result is complete and free, and no email address is required anywhere.

The result is indicative The tool reads public DNS records at the moment of the query and nothing else. It does not verify that sending servers really sign messages, that anyone reads the aggregate reports, or how a particular recipient will behave — every mail system evaluates the rules its own way. The result therefore does not mean that the rest of your mail traffic is in order, nor that it is not. DNS also answers from cache, so a recent change may not show up straight away.

Enter the domain name on its own — example.cz, not an address like [email protected] and not a link with https://. Input with an at sign or a slash is rejected. Internal and reserved names are rejected deliberately. The result is cached for a few minutes. The number of checks is limited twice over: by how many you send, and by how many run per minute against a single domain across all visitors together.

What the check does not do

Content valid as of 8 August 2026

SPF, DKIM and DMARC are one place out of several.

The check shows the state of one domain at one moment. The domain portfolio, the sending services and the settings around them can be gone through as part of a security assessment.

Write to us