Domain Check Tool

Check your domain for DMARC, SPF, MX, DKIM, BIMI, TLS-RPT, MTA-STS, and other email security records.

How It Works

Domain Scan

The tool queries public DNS servers then parses the relevant email authentication records. The results are then fed into a policy engine that highlights broken syntax, weak policy, and missing protections.

Public DNS lookup
The checker reads the public DNS records that mailbox providers can see for the domain.
Authentication analysis
DMARC, SPF, DKIM, BIMI, TLS-RPT, and MTA-STS records are evaluated for syntax, coverage, and policy quality.
Actionable issues
The results highlight missing protections, risky settings, and misconfigurations that affect deliverability and spoofing resistance.
Domain Check Results

Issue Detection

What issues does it scan for?

The checker looks for the failures that usually block DMARC enforcement, reduce deliverability, or leave gaps in your sender authentication setup.

spf checks

TitleDescriptionDocumentation
SPF DNS Lookup FailureWe could not look up the SPF record.RFC 7208 - SPF Record Lookup
Multiple SPF RecordsThe domain has more than one SPF record.RFC 7208 - Multiple DNS Records
Missing SPF RecordThe domain has no SPF record.RFC 7208 - Sender Policy Framework: SPF Records
Invalid Version TagThe record does not start with 'v=spf1'.RFC 7208 - SPF Records
Unable to parse SPF recordThe SPF record could not be parsed.RFC 7208 - SPF Records
Leading Whitespace Before SPF VersionThe SPF record starts with extra whitespace before 'v=spf1'.RFC 7208 - SPF Records
Incorrect SPF Version CasingThe SPF record uses the wrong casing for 'v=spf1'.RFC 7208 - SPF Records
DNS Lookup LimitThe SPF record uses more than 10 DNS lookups.RFC 7208 - DNS Lookup Limits
Void DNS Lookup LimitThe SPF record has more than 2 empty DNS lookups.RFC 7208 - DNS Lookup Limits
MX DNS Lookup LimitAn SPF 'mx' mechanism returns more than 10 hosts.RFC 7208 - MX Mechanism
Prefer ip4 over aThe SPF record uses an 'a' mechanism that resolves to only a small number of IPv4 addresses.RFC 7208 - DNS Lookup Limits
Mx records already includedThe SPF record uses 'mx' even though the MX provider is already covered by an SPF include.RFC 7208 - DNS Lookup Limits
Top-level missing 'all' or 'redirect'The top-level SPF record has no 'all' or 'redirect'.RFC 7208 - Default Result
Nested SPF record missing 'all' or 'redirect'An included SPF record has no 'all' or 'redirect'.RFC 7208 - Default Result
Permissive 'all' MechanismThe SPF record ends with '+all'.RFC 7208 - The 'all' Mechanism
Usage of 'ptr' MechanismThe SPF record uses 'ptr'.RFC 7208 - 'ptr' (do not use)
Unknown ModifierThe SPF record has an unknown modifier.RFC 7208 - SPF Modifiers
Syntax Error in MechanismThe SPF record has a mechanism syntax error.RFC 7208 - Mechanism Definitions
Duplicate entriesThe SPF record has duplicate mechanisms.RFC 7208 - Mechanism Definitions

dkim checks

TitleDescriptionDocumentation
Unable to parse DKIM recordThe DKIM record could not be parsed.RFC 6376 - DKIM Key Records
DKIM Public KeyThe DKIM record has no public key.RFC 6376 - DKIM Key Representation
DKIM Key LengthThe DKIM RSA key is shorter than 1024 bits.RFC 8301 - Cryptographic Algorithm Recommendations
DKIM Testing ModeThe DKIM record is in testing mode.RFC 6376 - Key Flags
DKIM Deprecated Hash AlgorithmThe DKIM record only allows SHA-1.RFC 8301 - Cryptographic Algorithm Recommendations

dmarc checks

TitleDescriptionDocumentation
DMARC DNS Lookup FailureWe could not look up the DMARC record.RFC 7489 - DMARC Policy Record
Multiple DMARC RecordsThe domain has more than one DMARC record.RFC 7489 - DMARC Policy Record
Missing DMARC RecordThe domain has no DMARC record.RFC 7489 - DMARC Policy Record
Invalid DMARC VersionThe DMARC record does not start with 'v=DMARC1'.RFC 7489 - DMARC Version
Unable to parse DMARC recordThe DMARC record could not be parsed.RFC 7489 - DMARC Record Format
Leading Whitespace Before DMARC VersionThe DMARC record starts with extra whitespace before 'v=DMARC1'.RFC 7489 - DMARC Version
Incorrect DMARC Version CasingThe DMARC record uses the wrong casing for 'v=DMARC1'.RFC 7489 - DMARC Version
Missing DMARC PolicyThe DMARC record has no policy tag.RFC 7489 - DMARC Policy
Invalid DMARC Policy OrderingThe DMARC policy tag is in the wrong position.RFC 7489 - DMARC Policy
Unknown or non-standard DMARC TagThe DMARC record has an unknown tag.RFC 7489 - DMARC Policy
Weak DMARC PolicyDMARC is set to monitoring only, allowing attackers to spoof email from the domain.RFC 7489 - Policy Actions
Partial DMARC EnforcementDMARC applies to less than 100% of mail.RFC 7489 - Percentage Tag
No Aggregate Reports ConfiguredNo aggregate report URI (rua) is configured. Reporting gives domain owners observability into which emails are failing authentication. It is not recommended to move to enforcement without enabling reporting.RFC 7489 - Aggregate Reports
Subdomain Policy on SubdomainThis subdomain record has an unused 'sp' tag.RFC 7489 - Subdomain Policy
Weak Subdomain PolicyThe subdomain policy is weaker than the main policy.RFC 7489 - Subdomain Policy
External Destination CheckThe external report domain is not verified. When sending reports to a different domain, the receiving domain must announce via DNS that it's willing to accept reports.RFC 7489 - Verifying External Dependencies

bimi checks

TitleDescriptionDocumentation
Unable to parse BIMI recordThe BIMI record could not be parsed.IETF BIMI Draft - Assertion Record Definition
Invalid BIMI VersionThe BIMI record does not start with 'v=BIMI1'.IETF BIMI Draft - Assertion Record Definition
Unknown BIMI record tagThe BIMI record has an unknown tag.IETF BIMI Draft - Assertion Record Definition
Missing BIMI Logo URIThe BIMI record has no logo URI.IETF BIMI Draft - Indicator Discovery
Missing BIMI Authority URIThe BIMI record has no authority URI.IETF BIMI Draft - Assertion Record Definition (a= Authority Evidence Location)
BIMI Logo URI Does Not ResolveThe BIMI logo URL does not load.IETF BIMI Draft - Indicator Discovery Without Evidence
BIMI Authority URI Does Not ResolveThe BIMI authority URL does not load.IETF BIMI Draft - Assertion Record Definition (a= Authority Evidence Location)

tlsrpt checks

TitleDescriptionDocumentation
Invalid TLS-RPT VersionThe TLS-RPT record does not start with 'v=TLSRPTv1'.RFC 8460 - DNS Record Syntax
Missing TLS-RPT ruaThe TLS-RPT record has no report address.RFC 8460 - rua Tag
Unable to parse TLS-RPT recordThe TLS-RPT record could not be parsed.RFC 8460 - DNS Record Syntax
Unknown TLS-RPT TagThe TLS-RPT record has an unknown tag.RFC 8460 - DNS Record Syntax

mta-sts checks

TitleDescriptionDocumentation
MTA-STS DNS Lookup FailureWe could not look up the MTA-STS record.RFC 8461 - The MTA-STS DNS TXT Record
Multiple MTA-STS RecordsThe domain has more than one MTA-STS record.RFC 8461 - The MTA-STS DNS TXT Record
Invalid MTA-STS VersionThe MTA-STS record has an invalid version.RFC 8461 - The MTA-STS DNS TXT Record
Unable to parse MTA-STS recordThe MTA-STS record could not be parsed.RFC 8461 - The MTA-STS DNS TXT Record
Missing MTA-STS idThe MTA-STS record has no 'id=' tag.RFC 8461 - The MTA-STS DNS TXT Record
Unknown MTA-STS TagThe MTA-STS record has an unknown tag.RFC 8461 - The MTA-STS DNS TXT Record
Missing MTA-STS PolicyThe MTA-STS policy file is missing.RFC 8461 - Policy Retrieval
Invalid MTA-STS PolicyThe MTA-STS policy file could not be parsed.RFC 8461 - MTA-STS Policies
MTA-STS Testing ModeThe MTA-STS policy is in testing mode.RFC 8461 - MTA-STS Policies
MTA-STS policy does not match published MXThe MTA-STS policy does not cover all MX hosts.RFC 8461 - MTA-STS Policies

sources checks

TitleDescriptionDocumentation
Google Workspace Source SetupGoogle Workspace appears to handle inbound mail for this domain, but either SPF or DKIM is not fully configured, or using a non-standard configuration.Google Workspace Admin Help: Set up SPFGoogle Workspace Admin Help: Set up DKIM
Mailchimp Source SetupMailchimp no longer requires the legacy servers.mcsv.net SPF include.Mailchimp Docs: Authentication and Delivery
Microsoft 365 Source SetupMicrosoft 365 appears to handle inbound mail for this domain, but outbound SPF or DKIM is not fully configured for Microsoft 365.Microsoft Learn: Set up SPF to identify valid email sources for your custom cloud domainsMicrosoft Learn: Set up DKIM to sign mail from your cloud domain

Ready for more?

Real-time DMARC monitoring, aggregate reports, and automated policy recommendations.

Benefits

  • Continuous deliverability monitoring
  • Fulfil Google/Yahoo sender requirements
  • Prevent Brand Impersonation
  • Improve Deliverability