SPF, DKIM & DMARC Checker
Check a domain’s MX, SPF, DMARC and DKIM records in one go, with plain-English findings and fixes for common mistakes.
If your email lands in spam, start here. Enter your domain to check MX, SPF, DKIM and DMARC together. The checker counts SPF DNS lookups (more than 10 breaks SPF), spots duplicate records, reads your DMARC policy and searches the common DKIM selectors – then tells you in plain English what to fix.
Reading the results
- SPF lists the servers allowed to send for your domain. One record only, ending in
~allor-all. - DKIM signs each message. Your mail provider gives you the record; the selector name is in the
s=tag of a received message’s DKIM-Signature header. - DMARC tells receivers what to do when SPF/DKIM fail and where to send reports. Start with
p=none, then move to quarantine and reject.
From the field
Most deliverability problems I fix come from a second SPF record added by a new service, or a forgotten include for a newsletter platform. Check after every new sending service you add.
Frequently asked questions
Do I need all three?
Since 2024 Gmail and Yahoo require SPF or DKIM for everyone and all three – plus alignment – for bulk senders. A domain with SPF, DKIM and a DMARC policy delivers far more reliably.
What does “too many DNS lookups” mean?
SPF allows at most 10 DNS-querying mechanisms (include, a, mx, ptr, exists, redirect). Beyond that receivers return permerror and SPF fails.
More tools
All tools →DNS Lookup
Look up A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, SRV and PTR records for any domain or IP address.
Open tool Email & DNSSPF Record Generator
Build a valid SPF TXT record for Microsoft 365, Google Workspace, your own mail server and sending services – with a lookup counter.
Open tool Email & DNSDMARC Record Generator
Create a DMARC policy record step by step – from monitoring (p=none) to full protection (p=reject) – with reporting addresses and alignment.
Open tool