Email security check: SPF, DKIM, DMARC
SPF, DKIM and DMARC are three DNS records that make it harder for others to send email in your domain's name. If they are missing or wrong, fraudsters can send fake invoices as you and your own email may land in spam. This tool reads your records, ranks the problems and tells you what to do.
Only public DNS records are read and no email is sent. To improve the tool and prevent abuse, the domain you check and the result are stored and deleted after 180 days.
Check your domain's email security
- 01
What do the three records do?
SPF lists which servers may send email for your domain. DKIM adds a signature to each outgoing email that receivers can verify. DMARC tells receivers what to do with email that fails SPF or DKIM: monitor (none), send to spam (quarantine) or reject; it also gets reports sent to you.
- 02
Gmail and Yahoo rules
Since February 2024, Google and Yahoo require SPF, DKIM and DMARC from bulk senders; email from domains without them can be rejected or sent to spam. Microsoft introduced similar rules for high-volume senders. Even if you send little email, correct records protect your delivery.
- 03
In what order should you fix things?
First list every service that sends email for you (mail provider, newsletter, invoicing, CRM). Then merge SPF into a single record and enable DKIM in each service. Start DMARC with p=none and a report address; once reports show legitimate mail passing, move to quarantine and then reject. Starting directly with reject can make legitimate email disappear too.
- 04
What can this tool not see?
DKIM selectors cannot be listed in DNS; the tool tries common ones, so if yours is different you need to enter it. The tool also cannot see where your email is actually sent from, whether your servers are blacklisted or content-related spam problems. For that, DMARC reports and sending logs have to be reviewed.
Frequently asked questions
What the tool checks, what it cannot check and how to use the result.
Are all three, SPF, DKIM and DMARC, needed?
Yes. SPF and DKIM alone do not tell receivers what to do; without DMARC, fake email can still be delivered. Major mailbox providers also expect all three together.
Is p=none enough?
It is right as a first step: it collects reports but does not stop fake email. Once reports show your legitimate mail passing, you should move to quarantine and reject.
Why should there not be two SPF records?
The standard (RFC 7208) requires a single SPF record per domain; with two records SPF fails completely. If you use several services, merge them into one record with include; total DNS lookups must not exceed 10.
Does this check store my domain or emails?
Your emails are not read and no email is sent; only public DNS records are read. The domain you check and the result are stored to improve the tool and prevent abuse, and deleted after 180 days. Your IP address itself is not stored, only a one-way hash.
Related pages
More free tools, related guides and services.
Let's talk about your project.
Tell us what you need; we will define the scope together.