Check your domain's email setup

Type a domain and watch its public DNS records get checked, step by step. You see what each step looks for, what it finds, and how to fix what is missing. Nothing is sent to the domain and you do not need an account.

What we look at

Mail servers
Where mail for the domain is delivered, and whether it is only forwarded to another inbox.
SPF
Which servers may send mail as the domain. A missing or broken record makes your mail more likely to be filtered.
DMARC
What Gmail, Outlook and Yahoo do with mail that fakes the domain. Without it, anyone can send as you.
DKIM
Whether a signing key is published, so receivers can tell your mail was not altered.

Questions about email authentication

How do I check if my domain has a valid SPF record?

SPF is a TXT record at the root of your domain that starts with v=spf1 and lists the servers allowed to send mail as you. A valid one exists exactly once, ends in ~all or -all, and needs no more than 10 DNS lookups. Type your domain into the checker above and it reads the record, counts the lookups and tells you what to change.

Why are my emails going to spam?

Missing or broken authentication is a common cause: no SPF record, no DKIM signature, no DMARC policy, or an SPF record over the 10-lookup limit. Spam folders are also affected by sending reputation, message content and recipient engagement, which DNS cannot show. This check covers the DNS part, so it can rule authentication in or out as the cause.

What does DMARC p=none mean?

p=none is the first of three steps. Receivers such as Gmail and Outlook send reports about mail that fails authentication, but they do not reject or quarantine any of it, so spoofed mail still reaches recipients. It is the right place to start, not the place to stop: read the reports for about two weeks, move to p=quarantine, and later to p=reject. A domain left at p=none is monitoring something nobody acts on.

How do I check if DKIM is working for my domain?

A DKIM public key is published as a TXT record at selector._domainkey.yourdomain.com, and the selector name is chosen by the service that sends your mail (google, selector1 and k1 are common). Selectors cannot be listed from outside, so the checker tries the common names and reports "not determined" rather than an error when it finds none. To be sure, send a mail to a Gmail address, open "Show original" and look for dkim=pass.

How many DNS lookups can an SPF record have?

Ten. RFC 7208 limits SPF evaluation to 10 DNS lookups, counting every include, a, mx, ptr, exists and redirect, including those inside the records you include. Above ten, receivers return a permanent error and SPF fails for every message. Removing services you no longer use is the usual fix.

Do I need SPF, DKIM and DMARC?

Since February 2024, Gmail and Yahoo require authentication for mail sent to them: SPF or DKIM for every sender, and SPF, DKIM and a DMARC record for bulk senders of about 5,000 messages a day or more. Setting up all three is the safe default for any domain that sends mail.

Is the domain check free, and does it send anything to my domain?

It is free and needs no account. It only reads public DNS records (MX, SPF, DMARC and common DKIM selector names) and sends nothing to the domain or its mail servers. Results are cached for ten minutes.

This check reads public DNS only: MX, SPF, DMARC and the most common DKIM selector names. A DKIM selector cannot be listed, so a key we do not find is reported as not determined, never as an error. The live view is slowed down so it can be followed; the answers are not. Results are kept for ten minutes.