Free · no signup
DMARC, SPF & DKIM Checker
Look up your domain’s email-security records and see exactly what to publish to stop spoofing.
SPF, DKIM & DMARC, in plain English
Without these three DNS records, anyone can send email that looks like it came from your domain — phishing your customers and staff, and quietly wrecking your deliverability. They work together:
- SPF publishes the list of servers allowed to send mail for you. End it with
-allto reject everyone else. - DKIM attaches a cryptographic signature so receivers can verify a message really came from you and wasn’t altered.
- DMARC ties SPF and DKIM together and tells receivers to
quarantineorrejectanything that fails — and emails you reports. Start atp=noneto observe, then tighten.
Frequently asked questions
It reads your domain’s public DNS records for SPF (authorized senders), DMARC (what to do with mail that fails) and DKIM (cryptographic signing), then flags anything missing or too permissive so attackers can’t spoof your domain.
SPF lists which servers may send mail for your domain. DKIM adds a signature that proves a message wasn’t altered. DMARC ties them together and tells receivers to quarantine or reject mail that fails — and where to send reports. You want all three.
p=none is monitoring only — your domain can still be spoofed. Once your reports look clean, move to p=quarantine and then p=reject. This checker shows you the exact record to publish.