Free · no signup

DMARC, SPF & DKIM Checker

Look up your domain’s email-security records and see exactly what to publish to stop spoofing.

SPF, DKIM & DMARC, in plain English

Without these three DNS records, anyone can send email that looks like it came from your domain — phishing your customers and staff, and quietly wrecking your deliverability. They work together:
  • SPF publishes the list of servers allowed to send mail for you. End it with -all to reject everyone else.
  • DKIM attaches a cryptographic signature so receivers can verify a message really came from you and wasn’t altered.
  • DMARC ties SPF and DKIM together and tells receivers to quarantine or reject anything that fails — and emails you reports. Start at p=none to observe, then tighten.

Frequently asked questions

It reads your domain’s public DNS records for SPF (authorized senders), DMARC (what to do with mail that fails) and DKIM (cryptographic signing), then flags anything missing or too permissive so attackers can’t spoof your domain.

SPF lists which servers may send mail for your domain. DKIM adds a signature that proves a message wasn’t altered. DMARC ties them together and tells receivers to quarantine or reject mail that fails — and where to send reports. You want all three.

p=none is monitoring only — your domain can still be spoofed. Once your reports look clean, move to p=quarantine and then p=reject. This checker shows you the exact record to publish.

Don’t check it once — watch it 24/7

A single DNS edit can weaken your DMARC policy without anyone noticing. CompleteStatus runs this exact check around the clock and alerts you the moment something changes — before your users (or attackers) notice.
Monitor this free Try the other free tools
Uptime is table stakes. We watch the rest — security headers, email authentication, certs and DNS, with the fix attached.
Start free
Company
© 2026 CompleteStatus. All rights reserved. CompleteStatus — operated in the United States · support@completestatus.com