Check your domain for DMARC, SPF, MX, DKIM, BIMI, TLS-RPT, MTA-STS, and other email security records.
How It Works
The tool queries public DNS servers then parses the relevant email authentication records. The results are then fed into a policy engine that highlights broken syntax, weak policy, and missing protections.

Issue Detection
The checker looks for the failures that usually block DMARC enforcement, reduce deliverability, or leave gaps in your sender authentication setup.
| Title | Description | Documentation |
|---|---|---|
| SPF DNS Lookup Failure | We could not look up the SPF record. | RFC 7208 - SPF Record Lookup |
| Multiple SPF Records | The domain has more than one SPF record. | RFC 7208 - Multiple DNS Records |
| Missing SPF Record | The domain has no SPF record. | RFC 7208 - Sender Policy Framework: SPF Records |
| Invalid Version Tag | The record does not start with 'v=spf1'. | RFC 7208 - SPF Records |
| Unable to parse SPF record | The SPF record could not be parsed. | RFC 7208 - SPF Records |
| Leading Whitespace Before SPF Version | The SPF record starts with extra whitespace before 'v=spf1'. | RFC 7208 - SPF Records |
| Incorrect SPF Version Casing | The SPF record uses the wrong casing for 'v=spf1'. | RFC 7208 - SPF Records |
| DNS Lookup Limit | The SPF record uses more than 10 DNS lookups. | RFC 7208 - DNS Lookup Limits |
| Void DNS Lookup Limit | The SPF record has more than 2 empty DNS lookups. | RFC 7208 - DNS Lookup Limits |
| MX DNS Lookup Limit | An SPF 'mx' mechanism returns more than 10 hosts. | RFC 7208 - MX Mechanism |
| Prefer ip4 over a | The SPF record uses an 'a' mechanism that resolves to only a small number of IPv4 addresses. | RFC 7208 - DNS Lookup Limits |
| Mx records already included | The SPF record uses 'mx' even though the MX provider is already covered by an SPF include. | RFC 7208 - DNS Lookup Limits |
| Top-level missing 'all' or 'redirect' | The top-level SPF record has no 'all' or 'redirect'. | RFC 7208 - Default Result |
| Nested SPF record missing 'all' or 'redirect' | An included SPF record has no 'all' or 'redirect'. | RFC 7208 - Default Result |
| Permissive 'all' Mechanism | The SPF record ends with '+all'. | RFC 7208 - The 'all' Mechanism |
| Usage of 'ptr' Mechanism | The SPF record uses 'ptr'. | RFC 7208 - 'ptr' (do not use) |
| Unknown Modifier | The SPF record has an unknown modifier. | RFC 7208 - SPF Modifiers |
| Syntax Error in Mechanism | The SPF record has a mechanism syntax error. | RFC 7208 - Mechanism Definitions |
| Duplicate entries | The SPF record has duplicate mechanisms. | RFC 7208 - Mechanism Definitions |
| Title | Description | Documentation |
|---|---|---|
| Unable to parse DKIM record | The DKIM record could not be parsed. | RFC 6376 - DKIM Key Records |
| DKIM Public Key | The DKIM record has no public key. | RFC 6376 - DKIM Key Representation |
| DKIM Key Length | The DKIM RSA key is shorter than 1024 bits. | RFC 8301 - Cryptographic Algorithm Recommendations |
| DKIM Testing Mode | The DKIM record is in testing mode. | RFC 6376 - Key Flags |
| DKIM Deprecated Hash Algorithm | The DKIM record only allows SHA-1. | RFC 8301 - Cryptographic Algorithm Recommendations |
| Title | Description | Documentation |
|---|---|---|
| DMARC DNS Lookup Failure | We could not look up the DMARC record. | RFC 7489 - DMARC Policy Record |
| Multiple DMARC Records | The domain has more than one DMARC record. | RFC 7489 - DMARC Policy Record |
| Missing DMARC Record | The domain has no DMARC record. | RFC 7489 - DMARC Policy Record |
| Invalid DMARC Version | The DMARC record does not start with 'v=DMARC1'. | RFC 7489 - DMARC Version |
| Unable to parse DMARC record | The DMARC record could not be parsed. | RFC 7489 - DMARC Record Format |
| Leading Whitespace Before DMARC Version | The DMARC record starts with extra whitespace before 'v=DMARC1'. | RFC 7489 - DMARC Version |
| Incorrect DMARC Version Casing | The DMARC record uses the wrong casing for 'v=DMARC1'. | RFC 7489 - DMARC Version |
| Missing DMARC Policy | The DMARC record has no policy tag. | RFC 7489 - DMARC Policy |
| Invalid DMARC Policy Ordering | The DMARC policy tag is in the wrong position. | RFC 7489 - DMARC Policy |
| Unknown or non-standard DMARC Tag | The DMARC record has an unknown tag. | RFC 7489 - DMARC Policy |
| Weak DMARC Policy | DMARC is set to monitoring only, allowing attackers to spoof email from the domain. | RFC 7489 - Policy Actions |
| Partial DMARC Enforcement | DMARC applies to less than 100% of mail. | RFC 7489 - Percentage Tag |
| No Aggregate Reports Configured | No aggregate report URI (rua) is configured. Reporting gives domain owners observability into which emails are failing authentication. It is not recommended to move to enforcement without enabling reporting. | RFC 7489 - Aggregate Reports |
| Subdomain Policy on Subdomain | This subdomain record has an unused 'sp' tag. | RFC 7489 - Subdomain Policy |
| Weak Subdomain Policy | The subdomain policy is weaker than the main policy. | RFC 7489 - Subdomain Policy |
| External Destination Check | The external report domain is not verified. When sending reports to a different domain, the receiving domain must announce via DNS that it's willing to accept reports. | RFC 7489 - Verifying External Dependencies |
| Title | Description | Documentation |
|---|---|---|
| Unable to parse BIMI record | The BIMI record could not be parsed. | IETF BIMI Draft - Assertion Record Definition |
| Invalid BIMI Version | The BIMI record does not start with 'v=BIMI1'. | IETF BIMI Draft - Assertion Record Definition |
| Unknown BIMI record tag | The BIMI record has an unknown tag. | IETF BIMI Draft - Assertion Record Definition |
| Missing BIMI Logo URI | The BIMI record has no logo URI. | IETF BIMI Draft - Indicator Discovery |
| Missing BIMI Authority URI | The BIMI record has no authority URI. | IETF BIMI Draft - Assertion Record Definition (a= Authority Evidence Location) |
| BIMI Logo URI Does Not Resolve | The BIMI logo URL does not load. | IETF BIMI Draft - Indicator Discovery Without Evidence |
| BIMI Authority URI Does Not Resolve | The BIMI authority URL does not load. | IETF BIMI Draft - Assertion Record Definition (a= Authority Evidence Location) |
| Title | Description | Documentation |
|---|---|---|
| Invalid TLS-RPT Version | The TLS-RPT record does not start with 'v=TLSRPTv1'. | RFC 8460 - DNS Record Syntax |
| Missing TLS-RPT rua | The TLS-RPT record has no report address. | RFC 8460 - rua Tag |
| Unable to parse TLS-RPT record | The TLS-RPT record could not be parsed. | RFC 8460 - DNS Record Syntax |
| Unknown TLS-RPT Tag | The TLS-RPT record has an unknown tag. | RFC 8460 - DNS Record Syntax |
| Title | Description | Documentation |
|---|---|---|
| MTA-STS DNS Lookup Failure | We could not look up the MTA-STS record. | RFC 8461 - The MTA-STS DNS TXT Record |
| Multiple MTA-STS Records | The domain has more than one MTA-STS record. | RFC 8461 - The MTA-STS DNS TXT Record |
| Invalid MTA-STS Version | The MTA-STS record has an invalid version. | RFC 8461 - The MTA-STS DNS TXT Record |
| Unable to parse MTA-STS record | The MTA-STS record could not be parsed. | RFC 8461 - The MTA-STS DNS TXT Record |
| Missing MTA-STS id | The MTA-STS record has no 'id=' tag. | RFC 8461 - The MTA-STS DNS TXT Record |
| Unknown MTA-STS Tag | The MTA-STS record has an unknown tag. | RFC 8461 - The MTA-STS DNS TXT Record |
| Missing MTA-STS Policy | The MTA-STS policy file is missing. | RFC 8461 - Policy Retrieval |
| Invalid MTA-STS Policy | The MTA-STS policy file could not be parsed. | RFC 8461 - MTA-STS Policies |
| MTA-STS Testing Mode | The MTA-STS policy is in testing mode. | RFC 8461 - MTA-STS Policies |
| MTA-STS policy does not match published MX | The MTA-STS policy does not cover all MX hosts. | RFC 8461 - MTA-STS Policies |
| Title | Description | Documentation |
|---|---|---|
| Google Workspace Source Setup | Google Workspace appears to handle inbound mail for this domain, but either SPF or DKIM is not fully configured, or using a non-standard configuration. | Google Workspace Admin Help: Set up SPFGoogle Workspace Admin Help: Set up DKIM |
| Mailchimp Source Setup | Mailchimp no longer requires the legacy servers.mcsv.net SPF include. | Mailchimp Docs: Authentication and Delivery |
| Microsoft 365 Source Setup | Microsoft 365 appears to handle inbound mail for this domain, but outbound SPF or DKIM is not fully configured for Microsoft 365. | Microsoft Learn: Set up SPF to identify valid email sources for your custom cloud domainsMicrosoft Learn: Set up DKIM to sign mail from your cloud domain |
Real-time DMARC monitoring, aggregate reports, and automated policy recommendations.
Benefits