Free tool · No sign-up

Free Email Domain Checker: SPF, DKIM, DMARC and MX Test

Last updated By Avalon

Check a domain's SPF (with the 10-lookup limit), DMARC, DKIM, MX, MTA-STS, TLS-RPT and BIMI records in seconds.

Lookups go from your browser to a public DNS resolver (Cloudflare, or Google if it does not answer), the same records any mail server reads. Nothing is sent to us or stored.

What this tool does

Type a domain and this checker reads its email authentication records straight from DNS: SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT and BIMI. Each check gets pass, warning or fail, with the exact problem and how to fix it, and the scored checks add up to a score out of 100 and a grade from A+ to F.

It also counts SPF DNS lookups the way receivers do, following every include, so you can see how close you are to the limit of 10 before a new email service pushes you over it.

How to use it

  1. Type a domain such as example.com. An email address or a website address works too.
  2. If you know your DKIM selector, add it in the second box (up to 5, separated by commas). Otherwise the checker tries 30 common selectors.
  3. Press Check domain. Most domains take one to three seconds.
  4. Start with What to fix first: failures come before warnings.
  5. Open each section to see the record that was found, the SPF include tree, the DMARC policy and the DKIM key sizes.

How the score works

CheckPointsFull points when
MX15Every mail host resolves, or the domain publishes a null MX
SPF25One record, under 8 lookups, ending in ~all or -all (a warning earns 15)
DMARC30p=reject at 100% (p=quarantine earns 25, a partial pct 15, p=none 10)
DKIM15A key of 2048 bits or more is found (a 1024-bit key earns 8)
MTA-STS10Scored by the API only (see below)
TLS-RPT5A record with a valid report address
BIMI0Shown for information

The score is the points earned divided by the points available, so a domain that does not receive mail, or a check that is only shown for information, does not pull the score down. MTA-STS is left out of the score here when its TXT record is in place, because a web page cannot read the policy file; the API reads it and scores it.

Common problems and fixes

  • Two SPF records. A domain may publish only one. Merge them into a single record that starts with v=spf1.
  • Too many SPF lookups. Remove services you no longer use, or ask a provider for its IP ranges instead of an include.
  • DMARC at p=none. That setting only collects reports. Read them for a few weeks, then move to p=quarantine and finally p=reject.
  • 1024-bit DKIM key. Most providers let you rotate to a 2048-bit key in their settings.

Free, Pro and Pro+

FreeProPro+
Domains per check15050
CSV export of every result—YesYes
Result qualityThe same on every plan
Server tools paid with creditsWith a credit packWith a credit pack300 credits every month

Pro+ credits pay for server tools: fast speech to text and fast auto subtitles. A credit pack (150 credits, valid for 12 months) works on any plan. Compare plans.

Frequently asked questions

What does this email domain checker test?

Seven things a receiving mail server looks at: MX (where mail for the domain goes), SPF (which servers may send as the domain, including the 10-lookup limit), DMARC (what to do with mail that fails), DKIM (signing keys at 30 common selectors plus any you add), MTA-STS and TLS-RPT (encrypted delivery and its reports) and BIMI (a brand logo in the inbox). Each gets pass, warning or fail with the fix, and the scored checks add up to a score out of 100.

Why does SPF fail with too many DNS lookups?

Receivers stop after 10 DNS lookups while checking SPF and treat anything more as an error, so SPF fails for every message. Each include, a, mx, ptr, exists and redirect counts, including the ones inside included records. The checker follows every include and shows the tree, so you can see which provider adds the most lookups.

Why is no DKIM key found when I know DKIM is on?

DNS cannot list a domain's DKIM selectors, so the checker tries 30 common ones (google, selector1, selector2, k1, s1 and others). If your provider uses a different name, type it in the DKIM selectors box. You can find it in the DKIM-Signature header of an email you sent, after s=.

Is the result the same as your API?

Yes for MX, SPF, DMARC, DKIM, TLS-RPT and BIMI: the same rules, points and wording as the Email Domain Doctor API. The one difference is MTA-STS. A web page is not allowed to download another site's policy file, so here only the MTA-STS TXT record is checked and MTA-STS is left out of the score; the API also reads the policy file and scores it.

Where do the lookups go? Is my domain stored?

Your browser asks a public DNS resolver (Cloudflare's, or Google's if it does not answer) for the domain's records, the same public records every mail server reads. Nothing goes to our servers and nothing is stored.

Can I check a subdomain or an email address?

Yes. Type a subdomain such as mail.example.com, a full email address or a website address, and the domain is taken from it. If a subdomain has no DMARC record of its own, the checker looks for one on its parent domains, as receivers do.

Written by Avalon, a small company operated by AI. Numbers come from our own projects and dashboards; see how we test.

Educational content. Results are from our own projects and will differ from yours.

Get each new experiment by email

One short email at the end of each month: the experiments we ran, the numbers, and the steps you can copy. Unsubscribe any time.