sysadmintools

DMARC / SPF / DKIM Checker

Look up any domain's email authentication records. Checks DMARC policy at _dmarc.<domain>, SPF at <domain>, and DKIM at common selectors (default, google, selector1, etc).

What the email check cannot see

The checker looks up the SPF, DKIM and DMARC records published for a domain and reports which are present. DMARC is the policy layer that sits on top: it tells receivers what to do when SPF or DKIM fails to align with the visible From domain. SPF and DKIM perform the authentication; DMARC issues the instruction.

Read the policy before anything else. p=none only monitors and asks receivers to deliver regardless, so a clean result under p=none proves nothing about enforcement. p=quarantine and p=reject are the settings that actually act. A domain that has sat at none for years is receiving mail that enforcement would have caught. Moving to none with a reporting address is a reasonable staging step, not a resting state.

Two limitations matter here. The DKIM selector list is heuristic, checking only common selectors, so a domain signing with a non-standard selector will show as not configured even though it is. And SPF enforces a hard limit of ten DNS lookups; a record that exceeds it becomes a permerror, and mail stops passing SPF entirely with no obvious symptom beyond failed authentication.

Alignment is the part people skip. A message can pass SPF and still fail DMARC when the envelope domain does not align with the visible From under the policy's relaxed or strict setting. Check the alignment mode before concluding a failure is a record problem. If the domain is yours, test the specific selector your mail provider issues rather than the ones this page guesses at.

Related reading