Email DNS Checker: SPF, DKIM and DMARC
This free email DNS checker looks up a domain's MX records, SPF record, DMARC policy and DKIM keys and grades each one: is SPF present exactly once and within the ten-lookup limit, does DMARC enforce a policy and collect reports, does a DKIM selector publish a key. Each failure comes with the record to add. Use it when email lands in spam or bounces.

Email DNS Checker
Domain and Server
About this tool
Since 2024 Gmail, Yahoo and Microsoft have required senders to authenticate email with SPF and DKIM and to publish a DMARC policy, and mail that fails is sent to spam or rejected. Most small businesses discover this when quotes and invoices stop arriving. The records live in DNS, where a typo, a second SPF record or a forgotten include breaks everything silently.
The checker queries the domain's DNS directly. It lists the MX records and names the mail provider where it can. It finds the TXT record starting v=spf1, checks that there is exactly one, parses its mechanisms, counts the ones that cost a DNS lookup against the limit of ten, and reads the all qualifier. It fetches _dmarc.domain and reads the policy, subdomain policy, percentage, report addresses and alignment settings. For DKIM it looks up the selector you give, or tries a list of common selectors, and confirms a public key is published.
DNS can only show what is published, not whether your mail server actually signs with the key or whether the addresses in your SPF are the ones that really send. DKIM selectors are private to each sender, so a domain can be perfectly set up with a selector the tool did not guess: enter it from your mail provider's settings. A DMARC policy of none passes the basic requirement but protects nobody; the checker says so.
Frequently asked questions
What do SPF, DKIM and DMARC each do?
SPF lists the servers allowed to send mail for your domain. DKIM adds a cryptographic signature to each message so receivers can verify it was not altered and came from you. DMARC tells receivers what to do when both fail (nothing, quarantine or reject) and where to send reports. You need all three.
Why is more than one SPF record a problem?
The SPF standard says a domain must have exactly one record starting v=spf1; receivers treat two as a permanent error and fail the check. It usually happens when a second service adds its own record instead of being merged into the first. Combine every include into one record ending with ~all or -all.
What is the SPF 10 lookup limit?
Receivers stop evaluating SPF after ten DNS lookups caused by include, a, mx, ptr, exists and redirect, and return a permanent error. Each include can pull in more lookups of its own. Remove services you no longer use, replace includes with ip4 entries where possible, or use an SPF flattening service.
Which DMARC policy should I use?
Start with p=none and a rua= address to collect reports for a few weeks, fix any legitimate sender that fails, then move to p=quarantine and finally p=reject. p=none satisfies the Gmail and Yahoo requirement but stops nobody from spoofing your domain; reject is the goal.
How do I find my DKIM selector?
It is in your mail provider's DNS setup instructions: Google Workspace uses google, Microsoft 365 uses selector1 and selector2, Zoho and others let you choose. You can also open a sent message's headers and read the s= value in the DKIM-Signature line. Enter it in the selector field to check that exact key.
