Skip to main content

Free · no signup

DMARC, SPF & DKIM Checker

Look up your domain’s email-security records and see exactly what to publish to stop spoofing.

SPF, DKIM & DMARC, in plain English

Without these three DNS records, anyone can send email that looks like it came from your domain — phishing your customers and staff, and quietly wrecking your deliverability. They work together:

  • SPF publishes the list of servers allowed to send mail for you. End it with -all to reject everyone else.
  • DKIM attaches a cryptographic signature so receivers can verify a message really came from you and wasn’t altered.
  • DMARC ties SPF and DKIM together and tells receivers to quarantine or reject anything that fails — and emails you reports. Start at p=none to observe, then tighten.

Frequently asked questions

It reads your domain’s public DNS records for SPF (authorized senders), DMARC (what to do with mail that fails) and DKIM (cryptographic signing), then flags anything missing or too permissive so attackers can’t spoof your domain.

SPF lists which servers may send mail for your domain. DKIM adds a signature that proves a message wasn’t altered. DMARC ties them together and tells receivers to quarantine or reject mail that fails — and where to send reports. You want all three.

p=none is monitoring only — your domain can still be spoofed. Once your reports look clean, move to p=quarantine and then p=reject. This checker shows you the exact record to publish.