Free tool
DMARC, SPF and DKIM checker
Enter a domain to read its SPF, DMARC and DKIM records, explained in plain words, with what to fix first.
Check a domain
Enter a domain you send email from.
SPF
Not checked yet.
DMARC
Not checked yet.
DKIM
Not checked yet.
The lookup goes from your browser straight to a public DNS resolver over HTTPS. Nothing about it reaches us, and nothing is stored. These records are public: anyone can read them.
How to use it
- Type the domain in your From address: for
sam@tallyline.example, typetallyline.example. A full address or a link works too. - Optionally add your DKIM selector. You find it in any email you sent: open it, show the original message, and read
s=in theDKIM-Signatureline. - Press Check. Each record is explained, with what to fix first.
If you send from a personal address on a large free mail service, you cannot change these records and do not need to: the provider publishes them for its own domain.
What good looks like
- SPF: exactly one record starting
v=spf1, listing only the services that send as you, at most 10 DNS lookups, ending~allor-all. - DKIM: a key published for every service that sends as you, 2048-bit where the service allows it.
- DMARC: one record at
_dmarc.yourdomain. Start withv=DMARC1; p=none; rua=mailto:dmarc@yourdomain, read the reports for a few weeks, then move top=quarantineand laterp=rejectonce all your own mail passes.
Large mailbox providers require bulk senders to publish DMARC, and p=none is enough for that rule. If you send a few dozen cold emails a day from your own mailbox, the same three records are still what keeps you out of spam.
Questions
What does p=none mean in DMARC?
Monitoring only. Mail that fails DMARC is delivered as if there were no policy, and if you set rua you get daily reports of who sends as your domain. It is the right first step, not the last one.
How many DNS lookups can SPF use?
Ten. Every include, a, mx, ptr, exists and redirect counts, including the ones inside included records. Past ten, receivers treat SPF as broken and it fails for every email.
Is ~all or -all better?
-all tells receivers to reject mail from servers not in your list; ~all asks them to accept it but treat it with suspicion. With DMARC in place, ~all is common and safe; -all is stricter once you are sure the list is complete.
More free tools: Cold email checker · Subject line checker · Cold email legal checker · Reply classifier · Gmail warm-up calculator. All of them run in your browser; nothing you type is sent to us.
See what it would write for you
Paste your website. Honest Intros learns what you sell and shows who it would write to, and what it would say.
Free to start. Nothing is sent until you approve it.