Working with lots of files?Avalon Pro adds bigger batches (up to {pro} files), one-click ZIP download, saved presets and your own file names.Bigger batches are part of Avalon ProThe free version takes up to {free} files at once. Avalon Pro takes up to {pro} in one batch, still processed on your device.One-click ZIP download is part of Avalon ProDownload all still saves every file for free, one by one. Avalon Pro puts all your results in a single ZIP file.Saved presets are part of Avalon ProSave your settings under a name and load them again in one click, on this device.Custom file names are part of Avalon ProChoose how your output files are named, for example {name}-{n} or {date}-{name}.A logo in your QR code is part of Avalon ProPut your logo in the middle of the code. The error correction goes to the highest level so phones can still read it.Bulk QR codes are part of Avalon ProPaste or upload a CSV list and get one QR code per row, named from a column, all in one ZIP file.Batch watermarks are part of Avalon ProAdd your name, website or logo to every image in the batch, with the position, size and opacity you choose.Metadata removal is part of Avalon ProStrip location, camera and date details from every photo before you share it, and see exactly what was removed.Saved scenarios are part of Avalon ProSave your numbers under a name, compare two scenarios side by side, and export them all as a CSV file.MP3 tags are part of Avalon ProWrite the title, artist, album, year and a cover image into every MP3 you extract, so music players show them properly.Page numbers are part of Avalon ProNumber every page when you save: choose the position, the format (1, Page 1, 1 / 12 or Page 1 of 12) and the first number. Everything else in this tool stays free.A/B thumbnail variants are part of Avalon ProDesign up to 3 versions of your thumbnail, see them side by side in a mock feed, and download them all in one ZIP file. Everything else in this tool stays free.Saved designs are part of Avalon ProSave your layouts, fonts and colors under a name and reuse them for every video, on this device.Working on several PDFs at once is part of Avalon ProThe free version works on one PDF at a time. Avalon Pro takes up to {pro} PDFs in one go and saves them as one ZIP file.Bulk barcodes from a list are part of Avalon ProPaste or upload a CSV list and get one barcode per row in a single ZIP file, or a printable label sheet PDF with a different barcode on every label. Single barcodes and full sheets of one barcode stay free.Saved details and invoice numbering are part of Avalon ProSave your business details and clients, number invoices automatically, and export a CSV list of every invoice you issue, all stored on this device. Making and downloading invoices stays free.Longer documents are part of Avalon ProThe free version converts documents of up to {free:pages_per_file} pages. Avalon Pro converts up to {pro:pages_per_file} pages per file.Converting several files at once is part of Avalon ProThe free version converts one file at a time. Avalon Pro takes up to {pro} files in one go and saves them as one ZIP file.Longer recordings and batches are part of Avalon ProThe free version transcribes one file at a time, up to {free:audio_minutes} long. Avalon Pro takes recordings up to {pro:audio_minutes}, up to {pro} files in one go, and saves every transcript in one ZIP file.Longer videos and batches are part of Avalon ProThe free version burns subtitles into one video of up to {free:burn_minutes}, and SRT and VTT downloads stay free. Avalon Pro burns subtitles into videos up to {pro:burn_minutes} long, up to {pro} videos in one go, with saved subtitle styles.Checking many domains at once is part of Avalon ProThe free checker runs the same full check on one domain at a time. Avalon Pro checks up to {pro} domains in one go and exports every result as a CSV file.Checking many metadata files at once is part of Avalon ProThe free validator runs the same full check on one file at a time. Avalon Pro checks up to {pro} metadata files in one go and exports every certificate, expiry date and issue as a CSV file.Enter a valid email.Sending…You're on the list. We'll email you when Pro opens.Couldn't sign up right now. Try again shortly.
Lookups go from your browser to a public DNS resolver (Cloudflare, or Google if it does not answer), the same records any mail server reads. Nothing is sent to us or stored.
Checking {domain}…Done in {secs} s with {queries} DNS lookups.Type a domain like example.com, or an email address.That does not look like a domain name. Type something like example.com.Enter at most 5 DKIM selectors."{s}" is not a valid DKIM selector.The public DNS resolvers did not answer. Check your connection and try again.Score {score} out of 100{queries} DNS lookups · checked {time}{n} passed{n} warnings{n} failed{n} for informationNothing to fix. Every scored check passed.PassWarningFailInfo{points} / {max} pointsNot scoredMX (where your mail is delivered)SPF (who may send as you)DMARC (what receivers do with spoofed mail)DKIM (message signing keys)MTA-STS (encrypted delivery to you)TLS-RPT (delivery security reports)BIMI (brand logo in the inbox)RecordMail servers{priority} {host}{n} addressesIPv6PolicyDNS lookups{n}{plus} of 10Void lookupsInclude treeFound at{where} (inherited from the parent domain)StrengthApplies toSubdomain policyAggregate reports toAlignmentDKIM {dkim}, SPF {spf}Selectors checkedKeys found{selector}: {type} {bits}{selector}: empty key (revoked)testing modePolicy fileLogoCertificateNonecontains SPF macros, not expandednot followed (limit already exceeded)loopno SPF recordDNS errorredirectfail (-all)softfail (~all)neutral (?all)pass (+all)neutral (no 'all', so it defaults to ?all)Could not read MX records (DNS timeout or server failure).Check that the domain's nameservers answer reliably.Null MX (RFC 7505): this domain declares that it does not receive email.No MX records — mail to this domain falls back to its A record or bounces.Publish MX records for your mail provider, or a null MX ('0 .') if the domain sends and receives no mail.MX points to an IP address, not a host nameDNS lookup failedHost does not resolveMX host {host}: {error}.Only one MX host — no fallback if it is down (fine for large hosted providers).Fix or remove MX hosts that do not resolve; senders retry them and delay delivery.{domain}: unknown modifier '{key}' (ignored by receivers).{domain}: unknown mechanism '{term}' — receivers treat the whole record as an error (permerror).{domain}: invalid {name} value '{arg}'.{domain}: 'ptr' is deprecated (RFC 7208) and slow; remove it.{kind} without a domain.SPF loop: {target} is included more than once in the chain.Could not read SPF of {target} (DNS error after retry) — if this persists, receivers return temperror.{kind} '{target}' has no SPF record — receivers treat this as permerror.{target} publishes {n} SPF records (permerror).Could not read TXT records (DNS error).No SPF record — anyone can claim to send mail from this domain.Publish 'v=spf1 -all' so nobody can send mail as this domain.Publish one SPF TXT record listing your senders, e.g. 'v=spf1 include:_spf.google.com ~all'.{n} SPF records published — receivers treat this as permerror (SPF fails everywhere).Merge all SPF records into a single 'v=spf1 ...' TXT record.SPF needs {n}{plus} DNS lookups; the limit is 10 (permerror).Remove unused includes, replace 'a'/'mx' with ip4/ip6 ranges, or flatten nested includes.SPF uses {n} of 10 DNS lookups — one more provider will break it.{n} void lookups (limit 2).'+all' authorises every server on the internet to send as this domain.Replace '+all' with '-all' or '~all'.SPF ends neutral — it does not tell receivers to reject unlisted senders.End the record with '~all' (or '-all' once DMARC reports look clean).SPF record is {n} characters — long records risk UDP truncation.Could not read the DMARC record (DNS error).No DMARC record — receivers get no policy for spoofed mail and you get no reports.Publish a TXT record at _dmarc.{domain}: 'v=DMARC1; p=none; rua=mailto:dmarc@{domain}' and move to p=quarantine, then p=reject, once reports are clean.{n} DMARC records — receivers ignore DMARC entirely when there is more than one.Invalid pct value '{v}'.Missing or invalid policy p='{p}' — the record is ignored.Policy is p=none — spoofed mail is still delivered; this is a monitoring setting.After checking DMARC reports, move to p=quarantine and then p=reject.Policy {p} applies to only {pct}% of failing mail.Raise pct to 100.No aggregate report address (rua) — you cannot see who sends mail as your domain.Add rua=mailto:dmarc-reports@{org} (or a DMARC reporting service).Subdomain policy sp=none leaves every subdomain open to spoofing.Consider p=reject for the strongest protection.strongmoderatepartialmonitoring onlyinvalidstrictrelaxedSelector '{s}' has an empty key (revoked).Selector '{s}': {error}.public key is not valid base64public key could not be parsedSelector '{s}' uses a {bits}-bit RSA key — receivers reject keys under 1024 bits.Selector '{s}' uses a {bits}-bit RSA key; 2048 bits is the current recommendation.Rotate to a 2048-bit DKIM key.Selector '{s}' is in testing mode (t=y).No DKIM key at selector(s): {list}.Domain does not handle mail (null MX); DKIM not required.No active DKIM key found at the common selectors checked. Selectors cannot be listed from DNS, so enter your provider's selector above to check it.Enable DKIM signing at your mail provider and publish its public key.No MTA-STS — mail to you can be downgraded to unencrypted SMTP by an attacker.Publish _mta-sts.{domain} TXT 'v=STSv1; id=<date>' and a policy at https://mta-sts.{domain}/.well-known/mta-sts.txt (start with mode: testing).MTA-STS TXT record has no id= value.The TXT record is in place. A browser page is not allowed to read the policy file itself, so its mode, MX list and max_age are not checked here and MTA-STS is left out of the score. Open the policy file below to check it, or use the API for the full check.No TLS-RPT record — you get no reports when senders fail to connect securely.Publish _smtp._tls.{domain} TXT 'v=TLSRPTv1; rua=mailto:tls-reports@{domain}'.TLS-RPT record has no valid rua (mailto: or https:).No BIMI record (optional: shows your logo in supporting inboxes; needs DMARC enforcement).BIMI needs DMARC p=quarantine or p=reject at pct=100; logos will not show.BIMI logo URL must be https.No VMC/CMC certificate (a=); Gmail and Apple Mail require one.Avalon Pro checks up to {pro} domains at a time; the first {pro} were kept.Add at least one domain, one per line.Checked {done} of {total}…Checked {total} domains.Stopped after {done} of {total}.not a domaincould not be checkedDomain,Score,Grade,MX,SPF,DMARC,DKIM,MTA-STS,TLS-RPT,BIMI,SPF lookups,DMARC policy,DKIM selectors found,Issues,Checked at
What this tool does
Type a domain and this checker reads its email authentication records straight from DNS: SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT and BIMI. Each check gets pass, warning or fail, with the exact problem and how to fix it, and the scored checks add up to a score out of 100 and a grade from A+ to F.
It also counts SPF DNS lookups the way receivers do, following every include, so you can see how close you are to the limit of 10 before a new email service pushes you over it.
How to use it
Type a domain such as example.com. An email address or a website address works too.
If you know your DKIM selector, add it in the second box (up to 5, separated by commas). Otherwise the checker tries 30 common selectors.
Press Check domain. Most domains take one to three seconds.
Start with What to fix first: failures come before warnings.
Open each section to see the record that was found, the SPF include tree, the DMARC policy and the DKIM key sizes.
How the score works
Check
Points
Full points when
MX
15
Every mail host resolves, or the domain publishes a null MX
SPF
25
One record, under 8 lookups, ending in ~all or -all (a warning earns 15)
DMARC
30
p=reject at 100% (p=quarantine earns 25, a partial pct 15, p=none 10)
DKIM
15
A key of 2048 bits or more is found (a 1024-bit key earns 8)
MTA-STS
10
Scored by the API only (see below)
TLS-RPT
5
A record with a valid report address
BIMI
0
Shown for information
The score is the points earned divided by the points available, so a domain that does not receive mail, or a check that is only shown for information, does not pull the score down. MTA-STS is left out of the score here when its TXT record is in place, because a web page cannot read the policy file; the API reads it and scores it.
Common problems and fixes
Two SPF records. A domain may publish only one. Merge them into a single record that starts with v=spf1.
Too many SPF lookups. Remove services you no longer use, or ask a provider for its IP ranges instead of an include.
DMARC at p=none. That setting only collects reports. Read them for a few weeks, then move to p=quarantine and finally p=reject.
1024-bit DKIM key. Most providers let you rotate to a 2048-bit key in their settings.
Free, Pro and Pro+
Free
Pro
Pro+
Domains per check
1
50
50
CSV export of every result
—
Yes
Yes
Result quality
The same on every plan
Server tools paid with credits
With a credit pack
With a credit pack
300 credits every month
Pro+ credits pay for server tools: fast speech to text and fast auto subtitles. A credit pack (150 credits, valid for 12 months) works on any plan. Compare plans.
Frequently asked questions
What does this email domain checker test?
Seven things a receiving mail server looks at: MX (where mail for the domain goes), SPF (which servers may send as the domain, including the 10-lookup limit), DMARC (what to do with mail that fails), DKIM (signing keys at 30 common selectors plus any you add), MTA-STS and TLS-RPT (encrypted delivery and its reports) and BIMI (a brand logo in the inbox). Each gets pass, warning or fail with the fix, and the scored checks add up to a score out of 100.
Why does SPF fail with too many DNS lookups?
Receivers stop after 10 DNS lookups while checking SPF and treat anything more as an error, so SPF fails for every message. Each include, a, mx, ptr, exists and redirect counts, including the ones inside included records. The checker follows every include and shows the tree, so you can see which provider adds the most lookups.
Why is no DKIM key found when I know DKIM is on?
DNS cannot list a domain's DKIM selectors, so the checker tries 30 common ones (google, selector1, selector2, k1, s1 and others). If your provider uses a different name, type it in the DKIM selectors box. You can find it in the DKIM-Signature header of an email you sent, after s=.
Is the result the same as your API?
Yes for MX, SPF, DMARC, DKIM, TLS-RPT and BIMI: the same rules, points and wording as the Email Domain Doctor API. The one difference is MTA-STS. A web page is not allowed to download another site's policy file, so here only the MTA-STS TXT record is checked and MTA-STS is left out of the score; the API also reads the policy file and scores it.
Where do the lookups go? Is my domain stored?
Your browser asks a public DNS resolver (Cloudflare's, or Google's if it does not answer) for the domain's records, the same public records every mail server reads. Nothing goes to our servers and nothing is stored.
Can I check a subdomain or an email address?
Yes. Type a subdomain such as mail.example.com, a full email address or a website address, and the domain is taken from it. If a subdomain has no DMARC record of its own, the checker looks for one on its parent domains, as receivers do.