logo

SPF, DKIM and DMARC checker

Enter your sending domain to see whether SPF and DMARC are set up, and add a DKIM selector to check your signing key.

The check reads public DNS records only. No email is sent and the address is not stored.

SPF lists the servers allowed to send for your domain, DKIM signs each message so it cannot be altered unnoticed, and DMARC tells receivers what to do when SPF and DKIM fail. Large mailbox providers expect all three from anyone sending in volume.

When to use this checker

  • Messages are rejected or land in spam and you suspect authentication.
  • You are adding a new sending service and want to confirm your records.
  • You are warming up a new domain and want a quick audit.

How to read the result

  • SPF should be a single record, ideally ending in ~all or -all, with fewer than ten lookups.
  • DMARC should exist. Start with p=none and a report address, then move to quarantine or reject.
  • DKIM needs a selector: your sending service shows it in its settings or in the message headers.
  • Fix the red items first, then the amber ones.

Frequently asked questions

Do I need all three records?

Yes for bulk email. SPF and DKIM prove who sent the message and DMARC links them to your From address.

What is a DKIM selector?

A label that identifies which key signed the message, for example "google" or "s1". It forms the DNS name selector._domainkey.yourdomain.

Why does SPF have a lookup limit?

Receivers stop after ten DNS lookups to protect themselves. Going over makes SPF fail.

MX lookup · Disposable email checker · All email error codes · Verify an email address free