One lookup, all three records
SPF, DKIM and DMARC are checked together, because a problem in one is usually explained by another. Reading them separately is how misconfigurations survive.
SPF, DKIM and DMARC checker
Enter a domain to read all three email authentication records in one check — what is published, what it means, and where it is incomplete.
An SPF record lists the hosts allowed to send mail using your domain, and ends with an instruction about everything else. The check reads the record, resolves its includes, counts the DNS lookups it costs against the RFC 7208 limit of 10, and reports the "all" mechanism. Two SPF records on one domain is a permanent error rather than a warning: receivers may ignore both.
DKIM publishes a public key at a selector under _domainkey, so receivers can verify the signature your mail server adds. DNS gives no way to list selectors — you can only ask for a name you already suspect — so this checks ten common platform defaults and any selector you supply. Nothing found at those names is not proof that DKIM is absent, and the tool will not report it as such.
A DMARC record at _dmarc sets the policy applied when SPF and DKIM do not pass, and the address where aggregate reports are sent. The check reports the policy, whether it is applied to all mail or a percentage, and whether reports are being collected at all — a policy with nowhere to report to hides the failures it was meant to reveal.
Each of these answers a specific result the checker can return.
When the SPF block reports 10 of 10 lookups used.
When more than one SPF record is found on the domain.
When DMARC is present but the policy reads p=none.
When all three records pass and mail still lands in spam.
When the records still authorise a provider you have left.
SPF, DKIM and DMARC are checked together, because a problem in one is usually explained by another. Reading them separately is how misconfigurations survive.
SPF is capped at 10 DNS lookups and nested includes count towards it. This follows the includes rather than counting the top line, which is where records quietly break.
Every result is read from live DNS. Where a record cannot be proven absent — DKIM selectors, which cannot be listed — the tool says so instead of implying it.
SPF lists which hosts may send for your domain. DKIM lets a receiver verify a signature on the message. DMARC tells receivers what to do when those checks fail, and asks them to report back. They work as a set: DMARC has nothing to act on unless SPF or DKIM is in place.
RFC 7208 caps an SPF record at 10 DNS lookups, and lookups inside an include count towards that total. Go over and the record returns a permanent error, at which point receivers stop evaluating it — so a record that looks complete stops working. This checker resolves the includes rather than counting only the top line.
Not necessarily. A DKIM key lives at a selector, and DNS provides no way to list the selectors a domain uses — you can only query a name you already know. We check ten common platform defaults. If your provider uses a different selector, enter it and check again.
No one can promise that. Correct authentication is what receivers check first, and getting it wrong is a reliable way to have mail treated badly — but placement also depends on sending reputation, content and recipient behaviour, which no DNS record controls.
Run the full SEO Checker — ten scored categories, a prioritised to-do list, and a shareable report.
Run a Free SEO Check