Why these records decide whether your mail arrives
Since 2024 Gmail and Yahoo have required bulk senders to authenticate their mail with SPF, DKIM and DMARC, and other large mailbox providers apply the same signals to everyone. A missing or broken record does not usually bounce mail outright; it quietly moves it to spam. This checker reads the records a receiving server reads and flags the mistakes that cause that.
SPF — which servers may send
SPF is a TXT record starting v=spf1 that lists the servers allowed to send as your domain. The rule people break most often is the 10-lookup limit (RFC 7208): every include, a, mx, exists and redirect costs a DNS lookup, and includes inside includes count too. Go over ten and receivers return a permanent error — SPF then fails for every message. The checker follows every include and shows the full tree so you can see where the lookups go. It also flags multiple SPF records, +all, the deprecated ptr mechanism, and includes that point at names that no longer exist.
DKIM — the signature on each message
DKIM keys live at selector._domainkey.yourdomain, and only the sending platform knows the selector. With the field left blank, the checker tries the selectors that common platforms use. If yours is not found, open any message you sent, find the DKIM-Signature header, and enter its s= value. Keys are checked for size: 1024-bit RSA still works but 2048-bit is the current recommendation.
DMARC — what to do when checks fail
DMARC, at _dmarc.yourdomain, tells receivers what to do with mail that fails SPF and DKIM alignment and where to send reports. p=none only monitors; p=quarantine sends failures to spam; p=reject refuses them. The usual path is to start at none with a rua= reporting address, read the reports until every legitimate sender passes, then tighten the policy. Subdomains without their own record inherit the parent domain’s policy, and the checker shows when that is happening.
MX, MTA-STS, TLS-RPT and BIMI
- MX — each mail server should resolve to an address and must not be a CNAME. A null MX (
0 .) says the domain accepts no mail at all. - MTA-STS — tells sending servers to insist on encrypted, authenticated delivery to you instead of falling back to plaintext.
- TLS-RPT — asks senders to report when encrypted delivery to you fails.
- BIMI — publishes a logo some inboxes show next to authenticated mail. It requires DMARC at quarantine or reject.
More free tools
Last reviewed 2026-10-02. Results come live from the servers named above; DNS Benchmark Pro does not cache, proxy or store them.