Skip to main content
DNS Benchmark Pro Real-time DoH latency analysis
Engine ready

Email DNS

SPF, DKIM & DMARC Checker

Everything receiving mail servers look up before they trust a message from your domain — checked in one go, with the problems explained in plain English.

Leave the selector blank to probe the selectors used by Google Workspace, Microsoft 365, Proton, Fastmail, Zoho and other common platforms.

Your browser sends every lookup directly to Cloudflare’s 1.1.1.1 resolver over DNS-over-HTTPS. Cloudflare sees your IP address and the names queried; DNS Benchmark Pro receives neither. See the privacy policy.

Why these records decide whether your mail arrives

Since 2024 Gmail and Yahoo have required bulk senders to authenticate their mail with SPF, DKIM and DMARC, and other large mailbox providers apply the same signals to everyone. A missing or broken record does not usually bounce mail outright; it quietly moves it to spam. This checker reads the records a receiving server reads and flags the mistakes that cause that.

SPF — which servers may send

SPF is a TXT record starting v=spf1 that lists the servers allowed to send as your domain. The rule people break most often is the 10-lookup limit (RFC 7208): every include, a, mx, exists and redirect costs a DNS lookup, and includes inside includes count too. Go over ten and receivers return a permanent error — SPF then fails for every message. The checker follows every include and shows the full tree so you can see where the lookups go. It also flags multiple SPF records, +all, the deprecated ptr mechanism, and includes that point at names that no longer exist.

DKIM — the signature on each message

DKIM keys live at selector._domainkey.yourdomain, and only the sending platform knows the selector. With the field left blank, the checker tries the selectors that common platforms use. If yours is not found, open any message you sent, find the DKIM-Signature header, and enter its s= value. Keys are checked for size: 1024-bit RSA still works but 2048-bit is the current recommendation.

DMARC — what to do when checks fail

DMARC, at _dmarc.yourdomain, tells receivers what to do with mail that fails SPF and DKIM alignment and where to send reports. p=none only monitors; p=quarantine sends failures to spam; p=reject refuses them. The usual path is to start at none with a rua= reporting address, read the reports until every legitimate sender passes, then tighten the policy. Subdomains without their own record inherit the parent domain’s policy, and the checker shows when that is happening.

MX, MTA-STS, TLS-RPT and BIMI

More free tools

Last reviewed 2026-10-02. Results come live from the servers named above; DNS Benchmark Pro does not cache, proxy or store them.