Free tool/Email deliverability

Check your SPF, DKIM and DMARC

Test any domain's email authentication in seconds. See every SPF include and lookup, your DKIM key strength and DMARC policy, and what Gmail and Yahoo require, with a fix for each problem.

  • Free, no signup
  • SPF, DKIM, DMARC, MX & BIMI
  • PDF & Excel report
  • Nothing stored
Try·
How it works

SPF, DKIM & DMARC checker in 3 steps

  1. 1

    Enter your domain

    Type a domain, a website address or any email address at the domain. Add your DKIM selector if you know it.

  2. 2

    We query your DNS live

    SPF with every nested include, DKIM keys, DMARC with parent-domain fallback, MX and BIMI, looked up in parallel.

  3. 3

    Fix what's broken

    Each record gets a status and the exact fix. Save the report as PDF, Excel or CSV, or jump to the SPF and DMARC generators.

What you get

Every record that decides whether your email is trusted

The same checks mailbox providers run, read straight from DNS and explained in plain English.

SPF lookup counter

Follows include and redirect through every level and counts DNS lookups against the RFC 7208 limit of 10, including void lookups and include loops.

SPF qualifier and syntax

Flags +all, ?all, a missing all, multiple SPF records, deprecated ptr, terms after all and invalid mechanisms.

DKIM key strength

Checks 18 common selectors plus your own, decodes each public key to read its RSA length, and spots revoked keys and testing mode.

DMARC policy breakdown

Every tag explained, with validation for p, sp, pct, rua and alignment, and inheritance from the parent domain for subdomains.

Gmail & Yahoo checklist

The 2024 bulk-sender requirements, marked from your DNS where possible and honestly labelled where DNS can't tell.

Shareable report

A score and grade, with PDF, a three-sheet Excel workbook (Summary, Records, Checklist) and a CSV of every finding.

Guide

How SPF, DKIM and DMARC work together

Email was built without a way to prove who sent a message. SPF, DKIM and DMARC are three DNS records that add that proof. Mailbox providers such as Gmail, Yahoo and Outlook check them on every message, and mail that fails is more likely to land in spam or be rejected.

SPF: which servers may send

SPF is a TXT record at your domain that starts with v=spf1 and lists the servers allowed to send for it, directly (ip4:, ip6:) or by including a provider's list (include:_spf.google.com). It ends with an all term that says what happens to everyone else: -all fail, ~all softfail, ?all neutral. SPF checks the envelope sender (the Return-Path address), not the From address people see.

Two rules break more SPF records than anything else. A domain may publish only one SPF record, and an SPF check may use at most 10 DNS lookups. Every include, a, mx, ptr, exists and redirect counts, including those nested inside your providers' records. Go over either limit and receivers return permerror, which counts as an SPF failure.

DKIM: a signature on every message

DKIM adds a cryptographic signature to each message. The signature names a domain (d=) and a selector (s=), and receivers fetch the public key from selector._domainkey.domain to verify it. Use a 2048-bit RSA key where your provider supports it; 1024-bit keys still work but are the minimum RFC 8301 allows.

To find your selector, open a message you sent, choose “Show original” in Gmail (or view the message source elsewhere), and look for the DKIM-Signature header. The value after s= is the selector. Enter it under Advanced in the checker above.

DMARC: tying it to your From address

DMARC, published at _dmarc.yourdomain.com, passes only when SPF or DKIM passes and the domain it checked is aligned with the From domain. Relaxed alignment (the default) accepts the same organizational domain, so mail signed by mail.acme.com aligns with acme.com; strict alignment needs an exact match. That's why a provider's shared DKIM signature doesn't help your DMARC: you need DKIM signed with your own domain.

Roll DMARC out in three stages:

  1. p=none with a rua= address. Receivers send daily aggregate reports showing every source sending as your domain.
  2. p=quarantine once every legitimate sender passes. Failing mail goes to spam. You can use pct= to apply it to part of your mail first.
  3. p=reject when reports stay clean. Spoofed mail is refused outright.

What Gmail and Yahoo require

RequirementAll sendersBulk senders
SPF or DKIMRequiredBoth required
DMARC (at least p=none)—Required
From domain aligned with SPF or DKIM—Required
One-click unsubscribe for marketing mail—Required
Spam rate below 0.3%RequiredRequired

Google defines bulk senders as those sending 5,000 or more messages a day to Gmail accounts, and once you qualify you stay a bulk sender. Track your spam rate in Google Postmaster Tools and aim to stay below 0.1%.

Ready to fix what the check found? Build a record with the SPF record generator and the DMARC record generator, then run this check again.

FAQ

Frequently asked questions

Can't find your answer? Read the Atlis docs.

How do I check my SPF, DKIM and DMARC records?

Enter your domain (or any email address at it) above. The checker reads your SPF record and follows every include, checks 18 common DKIM selectors plus any you add, reads your DMARC policy at _dmarc.yourdomain, and looks up your MX and BIMI records. Each record gets a status, the raw value, a breakdown of its tags and a fix for anything wrong.

Why does the checker say it couldn't find my DKIM record?

DKIM keys live at <selector>._domainkey.<domain>, and there's no way to list the selectors a domain uses. We try common ones such as google, selector1 and s1, but providers like Amazon SES, Postmark and Brevo use random or dated selectors. Open an email you sent, view the original, find the DKIM-Signature header and enter the value after s= under Advanced.

What is the SPF 10 DNS lookup limit?

RFC 7208 limits an SPF check to 10 terms that need a DNS lookup: include, a, mx, ptr, exists and redirect. Includes inside includes count too. If a check goes over 10, receivers return permerror and SPF fails for your mail. ip4 and ip6 don't count, so replacing unused includes or stable a and mx terms with IP ranges brings the count down.

Should I use ~all or -all in my SPF record?

Both are fine once DMARC is enforced. ~all (softfail) marks unlisted servers as suspicious, and -all (fail) says they're not allowed. With DMARC at quarantine or reject, DMARC decides what happens to failing mail, so ~all is a common, safe choice. Never use +all, which lets anyone send as your domain.

Is p=none enough for DMARC?

p=none meets the Gmail and Yahoo bulk-sender minimum, and it's the right place to start because aggregate reports show who sends as your domain. But it asks receivers to take no action on mail that fails, so it doesn't stop spoofing. Move to p=quarantine and then p=reject once every legitimate sender passes.

What do Gmail and Yahoo require from bulk senders?

Since February 2024, senders of 5,000 or more messages a day to Gmail accounts must set up SPF and DKIM, publish DMARC with at least p=none, align the From domain with SPF or DKIM, offer one-click unsubscribe (RFC 8058) in marketing mail, and keep their spam rate below 0.3%. Yahoo applies similar rules. DNS can show the first three; the rest depend on your mail.

Why do I have two SPF records, and is that a problem?

It usually happens when a new email service tells you to add its SPF record and the old one is left in place. A domain may publish only one v=spf1 record; with two or more, every SPF check returns permerror. Merge them into one record with all the includes and a single all at the end.

Is this check private?

Yes. The domain is looked up in public DNS when you run the check and nothing is stored. The report exists only in your browser and in any PDF, Excel or CSV file you save.

Atlis

Authenticated domain? Put it to work.

Atlis watches what every new user does after signup and sends lifecycle emails automatically: onboarding nudges, re-engagement and failed-payment recovery. Emails go out with your own sender name and email, and every one includes one-click unsubscribe headers.

Start free

Free plan · No credit card · 10-minute setup