Skip to content
Email & DNS

SPF, DKIM & DMARC Checker

Check a domain’s MX, SPF, DMARC and DKIM records in one go, with plain-English findings and fixes for common mistakes.

Leave empty to try the common ones.
Public DNS data only – nothing is stored.

If your email lands in spam, start here. Enter your domain to check MX, SPF, DKIM and DMARC together. The checker counts SPF DNS lookups (more than 10 breaks SPF), spots duplicate records, reads your DMARC policy and searches the common DKIM selectors – then tells you in plain English what to fix.

Reading the results

  • SPF lists the servers allowed to send for your domain. One record only, ending in ~all or -all.
  • DKIM signs each message. Your mail provider gives you the record; the selector name is in the s= tag of a received message’s DKIM-Signature header.
  • DMARC tells receivers what to do when SPF/DKIM fail and where to send reports. Start with p=none, then move to quarantine and reject.

From the field

Most deliverability problems I fix come from a second SPF record added by a new service, or a forgotten include for a newsletter platform. Check after every new sending service you add.

Frequently asked questions

Do I need all three?

Since 2024 Gmail and Yahoo require SPF or DKIM for everyone and all three – plus alignment – for bulk senders. A domain with SPF, DKIM and a DMARC policy delivers far more reliably.

What does “too many DNS lookups” mean?

SPF allows at most 10 DNS-querying mechanisms (include, a, mx, ptr, exists, redirect). Beyond that receivers return permerror and SPF fails.