Email Security

Will your email reach the inbox?

This tool queries your domain's live DNS and shows you the actual SPF, DMARC, DKIM and MX records. If someone can currently send email pretending to be you, you will see exactly why.

Runs live DNS-over-HTTPS queries from your browser. Nothing is sent to our servers.

This tool runs DNS-over-HTTPS queries directly from your browser against Cloudflare's public resolver. It reads your real TXT and MX records and displays them verbatim. Because the lookups happen in your browser, nothing about your domain is sent to Live Ajans at all.

The guide behind this tool SPF, DKIM and DMARC: Getting Email Authentication Right Why your invoices land in spam, and how anyone can currently send email as your company. Configuring SPF, DKIM and DMARC without breaking mail. Read the guide · 6 min read →

What this tool checks

Live DNS queries from your own browser. Your domain is never sent to our servers.

  • SPF record

    Which servers may send as you, how many of the 10 permitted DNS lookups it uses, and how it ends.

  • DMARC policy

    Whether spoofed mail is rejected, quarantined, or — most commonly — monitored and delivered anyway.

  • DKIM signature

    Tested across the selectors the major providers use. Inconclusive rather than failed when yours is custom.

  • MX records

    Whether the domain can receive email at all.

  • Spoofability

    A plain answer to: can someone currently send email pretending to be you?

  • Raw record text

    The actual published records, verbatim, so you can see exactly what is there.

How to read your result

No DMARC record means your domain is spoofable right now. Anyone can send email claiming to be you, and receiving servers have no instruction to stop them. Invoice fraud against your customers works exactly this way.

DMARC at p=none is not protection. It evaluates, reports, and delivers anyway. It is the correct starting point — you need the reports to discover every legitimate sender before you start rejecting — but a domain that has sat at p=none for two years has the appearance of protection without the substance.

SPF over 10 DNS lookups fails permanently, and the symptom is legitimate mail being rejected. It creeps up as you add services: Google Workspace plus a CRM plus a marketing platform plus a helpdesk.

SPF ending in +all authorises the entire internet to send as you. It is worse than no SPF at all, and it usually appears because someone was debugging a delivery problem and never reverted it.

An inconclusive DKIM result is not a failure. Selectors are provider-specific and cannot be enumerated from outside. Your provider's DNS instructions name yours.

What these records do

SPF — who is allowed to send as you

A TXT record listing the servers permitted to send email from your domain. Without it, receiving servers have no way to distinguish your mail from a forgery. Watch for more than ten DNS lookups in the record, which causes SPF to fail entirely, and for a +all ending, which authorises the entire internet to send as you.

DKIM — cryptographic proof

A signature added to outgoing mail, verified against a public key in your DNS. It proves the message genuinely came from your domain and was not altered in transit. DKIM uses arbitrary selector names, so a public checker can only test common ones — your provider's documentation lists yours.

DMARC — the policy that ties it together

Tells receiving servers what to do when SPF or DKIM fails: nothing (p=none), quarantine, or reject. A large share of domains publish p=none and never move past it, which means the record exists but blocks no spoofing at all. It also enables reports showing who is sending mail as you.

MX — where your mail arrives

The servers that receive email for your domain. A missing or misconfigured MX record means inbound mail fails outright.

Why this matters commercially

Google and Yahoo now enforce authentication requirements for bulk senders. Domains without proper SPF, DKIM and DMARC increasingly land in spam or are rejected. If you send invoices, order confirmations or any marketing email, this is revenue infrastructure.

Frequently asked questions

How does this check my records without a server?

It uses DNS-over-HTTPS, a standard protocol that lets a browser query DNS directly. Your domain is sent to Cloudflare's public resolver and the results come straight back to your browser. We never see the query.

Why does DKIM show as inconclusive?

DKIM records live under a selector name that each email provider chooses — there is no universal location to check. We test the common selectors used by Google Workspace, Microsoft 365, and the major email service providers. If yours uses a custom selector, the check cannot see it, and the tool says inconclusive rather than claiming it is missing.

My DMARC record exists but the tool warns about it. Why?

Almost certainly because it is set to p=none, which is monitoring only — it collects reports but permits spoofed mail to be delivered. It is the correct starting point, but staying there indefinitely means you have the record without the protection.

Can you fix these records for us?

Yes. Email authentication is part of our technical work — configuring SPF, DKIM and DMARC correctly, moving DMARC to an enforcing policy safely without breaking legitimate mail, and setting up report monitoring.

Other free tools

SEO & Speed Audit

Real Core Web Vitals from Google's API, plus live on-page checks against your actual HTML.

Tell us what you are trying to grow.

One team. Three offices. Twenty-six languages. Send us the problem and you get a senior answer — not a sales script.

A written proposal within one business day, in your language.