What this tool checks
- MX records and null MX
- SPF record, default rule (-all/~all) and the 10-lookup limit
- DMARC policy (none/quarantine/reject), coverage and reporting
- DKIM key under common selectors
- MTA-STS, TLS-RPT and BIMI
How to use it
- 01
Enter the domain from your email address (example.com for [email protected]).
- 02
Press Analyze.
- 03
Fix the red rows first; the DMARC policy and SPF default rule usually make the biggest difference.
Technical details
SPF lookup limit
RFC 7208 allows at most 10 DNS lookups while evaluating SPF. The tool follows include and redirect chains like a real receiver and counts the total.
Moving to DMARC enforcement safely
Start with p=none and watch the rua reports; once every legitimate sending source aligns with SPF or DKIM, move to quarantine and then reject.
DKIM and selectors
DKIM keys are published under a selector name and can't be listed. The tool tries the selectors of common providers; not finding one doesn't prove DKIM is missing.
Frequently asked questions
Is DMARC p=none enough?
No. p=none only reports; spoofed mail is still delivered. Once your reports are clean, move to quarantine or reject.
Should I use ~all or -all?
With DMARC enforced, ~all is a common and safe choice. Without DMARC, -all sends a clearer signal. Either way, make sure every sending service is included in SPF.
What about domains that never send email?
Publish an SPF record of “v=spf1 -all”, a DMARC policy of “p=reject” and a null MX record. Then the domain can't be used for spoofing.
I use Google Workspace or Microsoft 365 — do I need anything else?
Yes. Add the provider's SPF include, enable DKIM in the admin console and create the DMARC record yourself; these are not fully configured by default.