SPF, DKIM and DMARC Checker

Find out whether criminals can send email that looks like it comes from your domain, and exactly which DNS records fix it.

Only the domain name is sent. DNS records are public information and the check reveals nothing about you.

Email was designed without any way to prove who sent a message. Three DNS records were added later to close that gap. SPF lists which servers may send mail for your domain. DKIM adds a signature that proves a message really came from you and was not changed. DMARC ties them together and tells every receiving mail server what to do with messages that fail: deliver them anyway, send them to spam, or reject them.

When those records are missing or set to monitoring only, anyone can send email that appears to come from your domain. Your customers, suppliers and staff receive it looking exactly like the real thing. This check reads your domain's public DNS, grades each record, tells you plainly whether the domain can be spoofed, and gives the specific fix for anything that is wrong.

How it works

  1. Enter a domain. You can paste a website address or an email address and the domain is extracted for you.
  2. The server looks up the domain's mail servers and identifies the email provider, such as Google Workspace or Microsoft 365.
  3. It reads the SPF record, checks there is exactly one, and follows every include to count the DNS lookups it needs, because the standard caps that at ten.
  4. It reads the DMARC record and decodes the policy, the percentage applied, and whether reports are being collected.
  5. It probes around forty common DKIM selector names, plus any selector you supply, and estimates the strength of each key found.
  6. It also checks MTA-STS, TLS reporting and BIMI, then combines everything into a grade from A to F with a score out of 100.

Reading your results

  • Grade A or B: SPF, DKIM and an enforcing DMARC policy are in place. Spoofed mail using your exact domain should be quarantined or rejected by major providers.
  • Grade C: the basics exist but something important is weak, most often a DMARC policy of none, which reports on spoofing but still lets it be delivered.
  • Grade D or F: key records are missing or broken. Criminals can send convincing mail as your domain today.
  • Can be spoofed or blocked: the plain answer. It depends mainly on whether DMARC is present and set to quarantine or reject.
  • SPF ending in -all is strict and best. ~all is a soft fail that relies on DMARC to act. +all or ?all effectively allows anyone and is a failure.
  • DMARC p=none means monitoring only. p=quarantine sends failures to spam. p=reject blocks them outright and is the goal.
  • More than ten SPF lookups makes the SPF check error out for receivers, which can cause your legitimate mail to fail.
  • A DKIM key of 1024 bits is considered weak. 2048 bits or more is the current recommendation.

How this fits into the real world

Invoice and payment fraud against small businesses often starts with a spoofed email. A message arrives from what looks like your address or your accountant's, telling a customer your bank details have changed. Without an enforcing DMARC policy, that message can land in the customer's inbox with nothing to mark it as fake.

Spoofing also damages your reputation with email providers. When criminals send spam or phishing as your domain, receivers learn to distrust it, and your genuine invoices and newsletters start going to spam.

Large providers now require this. Since February 2024, Gmail and Yahoo require bulk senders to authenticate with SPF and DKIM and to publish a DMARC record, and many organisations and government agencies expect DMARC at quarantine or reject from their suppliers.

The fix is usually a small number of DNS changes. Most email providers publish the exact SPF and DKIM values to add. The safe path to DMARC is to start at p=none with reporting, confirm all your legitimate senders pass, then move to quarantine and finally reject.

Who this is for

  • Small business owners and sole traders with email on their own domain.
  • Anyone whose customers or suppliers have received fake emails in their name.
  • IT providers and web developers auditing a client's domain.
  • Anyone about to send marketing or invoices from a new domain who wants to reach the inbox.

What this tool cannot tell you

  • DKIM selector names are chosen by whoever set up the email, so a custom selector we do not try can be missed. Add it in the optional field if you know it.
  • It reads DNS as it is now. Recent changes can take time to appear because of DNS caching.
  • It checks that the records exist and are well formed. It does not send test mail, so it cannot confirm every one of your sending services actually passes.
  • It protects your exact domain. Lookalike domains registered by criminals are a separate problem that these records cannot stop.

Frequently asked questions

What is the difference between SPF, DKIM and DMARC?

SPF is a list of servers allowed to send mail for your domain. DKIM is a digital signature proving a message came from your domain and was not changed. DMARC checks that the address people see matches a domain that passed SPF or DKIM, and tells receivers what to do when it does not. You need all three.

Do I need DMARC if I only send a few emails a day?

Yes. DMARC protects against other people sending as you, which has nothing to do with how much you send. Small businesses are frequent targets for invoice fraud precisely because their domains are often unprotected.

What does p=none mean in a DMARC record?

It means monitoring only. Receivers send you reports about mail using your domain, but they still deliver messages that fail. It is the right place to start, but it does not stop spoofing until you move to quarantine or reject.

How do I find my DKIM selector?

Open an email sent from your domain, view its raw headers, and find the DKIM-Signature header. The value after s= is the selector. Your email provider's admin console also shows it where DKIM is set up.

Why does my SPF record fail with too many DNS lookups?

Each include in SPF, and each include inside those, counts toward a limit of ten lookups. Adding many services such as a CRM, a newsletter tool and a helpdesk can go over. Remove services you no longer use, or consolidate senders, so the total is ten or fewer.

Does DMARC stop phishing?

It stops phishing that uses your exact domain, which is the most convincing kind. It cannot stop lookalike domains that swap a letter or add a word, so staff and customers still need to check sender addresses carefully.

Related tools

Guides that go with this tool