Security

Email DNS Checker

Check the four DNS records that decide whether your email reaches the inbox: MX, SPF, DKIM and DMARC. Enter a domain and get a letter grade, the raw records, and copy-ready fixes for anything missing or misconfigured.

What the email DNS checker does

Every message you send is judged by the receiving server before anyone reads it. That server looks up your domain's DNS and asks four questions. Do MX records exist, so the domain can receive replies and bounces? Does an SPF record list which servers may send on the domain's behalf, and how strictly should unlisted senders be treated? Is there a DKIM public key so the signature on the message can be verified? And does a DMARC policy tell the receiver what to do when SPF or DKIM fail, and where to send reports? This tool performs those lookups live, analyzes the results, and rolls them into a single grade from A to F.

How to use it

  • Enter your domain, for example example.com, without www or https.
  • Optionally enter your DKIM selector. If you leave it blank, the tool tries common selectors such as default, google, selector1 and selector2, plus selectors matched to your detected mail provider.
  • Read the grade, then work through the findings. Errors come first, followed by improvements.
  • Copy the example records directly into your DNS provider's control panel and check again after propagation.

For SPF the tool reports the "all" qualifier and estimates how many DNS lookups the record consumes, because more than ten causes SPF to fail outright. For DMARC it shows the policy, whether aggregate reports are configured, and how to move safely from monitoring to enforcement.

Why it matters

Major mailbox providers now require SPF and DKIM for anyone sending in volume, and a DMARC record for every sending domain. Without them, legitimate newsletters, invoices and password resets land in spam or are rejected silently. Just as important, a domain without an enforcing DMARC policy can be spoofed by anyone, which is how most invoice fraud and phishing campaigns begin. A correct setup takes three DNS records and about twenty minutes, yet a large share of business domains still fail at least one check.

If you would rather not manage this yourself, our business email hosting comes with SPF, DKIM and DMARC configured on every domain we host, and we monitor the records so a DNS change never quietly breaks your deliverability. You can also confirm the underlying records with the DNS lookup tool or review ownership details with the WHOIS lookup.

FAQ

Frequently asked questions

What is a good grade?
An A means MX, SPF with a strict qualifier, DKIM and an enforcing DMARC policy with reporting are all in place. A B is solid and usually means one soft setting, such as ~all or p=quarantine, could be tightened. Anything below a C indicates a missing record that is actively hurting deliverability.
The tool says DKIM was not found, but my provider says it is enabled. Why?
DKIM records live under a selector name that varies by provider. Open a message you sent, view the original headers, and look for s= in the DKIM-Signature line. Enter that value in the selector field and run the check again.
Should I use -all or ~all in SPF?
Use ~all (soft fail) while you are still discovering every service that sends on your behalf. Once your DMARC reports show all legitimate mail passing, switch to -all so unauthorized senders are rejected outright.
What DMARC policy should I start with?
Start with p=none and a rua= reporting address so you can see who is sending as your domain without affecting delivery. After a few weeks of clean reports, move to p=quarantine, then p=reject.
How long do DNS changes take to show up?
Most records propagate within minutes, but the previous value can be cached for up to the record's TTL, often one hour. This tool caches results for ten minutes, so wait a little and check again after editing your DNS.
Need the real thing?

We build the sites and systems these tools measure.

Digzy Technology designs fast, search-friendly websites, stores and apps. Tell us what you have in mind.

Chat with us