A check of SPF, DMARC and DKIM from public DNS. It shows whether fraudulent mail can be sent in the name of your domain and how strict the current rules are.
Enter a domain and the tool reads the records from public DNS that receiving servers use to decide whether a message carrying your address is genuine. Each section explains what it means and what to do about the finding.
The check sends nothing and connects to nothing except DNS. You can run it on someone else's domain — it is the same information every mail server in the world has about it. The result is complete and free, and no email address is required anywhere.
The result is indicative
The tool reads public DNS records at the moment of the query and nothing else. It does not verify that sending servers really sign messages, that anyone reads the aggregate reports, or how a particular recipient will behave — every mail system evaluates the rules its own way. The result therefore does not mean that the rest of your mail traffic is in order, nor that it is not. DNS also answers from cache, so a recent change may not show up straight away.
What the check does not do
It reads nothing but public DNS. It sends no mail, does not connect to your mail server and does not look into mailboxes.
It will not confirm that sending servers really sign messages. That shows only in the headers of a message that has actually been sent.
It will not guess every DKIM selector. It tries only a few of the most common ones, because they cannot be listed from the outside.
It will not say how a particular recipient behaves. Every mail system evaluates the same record a little differently.
It is no substitute for DMARC aggregate reports. Who sends in your name shows only in data collected over time.
It is not evidence that a legal or contractual requirement has been met.
Content valid as of 8 August 2026
SPF, DKIM and DMARC are one place out of several.
The check shows the state of one domain at one moment. The domain portfolio, the sending services and the settings around them can be gone through as part of a security assessment.
Google Analytics loads even without your consent — without it, it runs in a limited, cookie-less mode, but Google still sees your IP address. Consent enables analytics cookies. We do not sell personal data; who we pass it to is described in the privacy policy.