Check a domain's SPF, DKIM, DMARC and MX records the way a receiving mail server reads them, with a plain-English explanation and an exact fix for anything that could send its mail to spam.
The part after the @ in an email address. Pasting a full address or a website URL works too. Common DKIM selectors are tried automatically.
The domain you enter, plus any DKIM selector, is sent to Cloudflare's public DNS resolver (or Google's, as a fallback) to look up its public DNS records. Nothing else you type leaves your browser.
What this checker reads, and why receivers care
A mail server receiving a message that claims to be from you@yourdomain.com has no built-in way to know whether you sent it. Instead it looks up a few public DNS records that you, as the domain owner, publish ahead of time. Together they answer three questions: which servers may send mail for the domain, whether the message carries a signature made with a key the domain controls, and what to do when neither check passes. This tool fetches those records the way a receiving server would, follows every reference inside them, and explains each result.
| Record | Where it lives | What it does |
|---|---|---|
| SPF | A TXT record at yourdomain.com starting v=spf1 | Lists the servers and services allowed to send as the domain. |
| DKIM | A TXT record at selector._domainkey.yourdomain.com | Publishes the public key that verifies each message's signature. |
| DMARC | A TXT record at _dmarc.yourdomain.com | Ties SPF and DKIM to the From address readers see, sets the policy for failures, and asks for reports. |
| MX | MX records at yourdomain.com | Names the servers that receive mail. Not authentication, but a sender that cannot receive replies looks wrong to filters. |
SPF: one record, ten lookups
An SPF record is a single line: v=spf1, then mechanisms such as ip4:, include: and mx, then an all term that covers every server not listed. Two rules cause most SPF failures.
First, a domain can have only one SPF record. When a newsletter tool or help desk tells you to "add an SPF record", it means add its include: to the record you already have. Publish a second record beside the first and SPF returns a permanent error for every message you send, including mail from your main provider.
Second, checking a record may cost at most 10 DNS lookups. Each include, a, mx, ptr, exists and redirect counts, and so does every one of those inside the records you include. Providers nest includes inside their own, so a single line can cost several. Past 10, receivers stop evaluating and SPF fails outright. The include tree in the results shows where every lookup goes, which is usually enough to spot the service you stopped using two years ago.
The ending matters less than people expect. -all asks receivers to reject servers you have not listed, ~all asks them to treat that mail as suspicious, and ?all expresses no opinion. Once DMARC is in place it decides what happens to failing mail, and ~all is the common choice, because some receivers reject an SPF hard fail before checking DKIM, which can cost you forwarded mail that DKIM would have saved. +all authorizes every server on the internet and is never right.
DKIM: why a checker has to guess
DKIM signs each outgoing message with a private key held by your sending service. The matching public key sits in DNS under a selector, a label the service chooses, at selector._domainkey.yourdomain.com. The selector travels inside each message, so receivers never need a list of them, and DNS offers no way to produce one. This tool tries the selectors common providers use. If yours is something else, such as the random tokens Amazon SES generates, guessing will not find it.
To find it, send yourself a message through the service, open it with Show original in Gmail or View source in most other mail apps, and look for the DKIM-Signature header. The s= tag is the selector and d= is the domain that signed. Enter the selector above to check that exact key. RSA keys should be 2048 bits. A 1024-bit key still verifies but falls below the RFC 8301 recommendation, and a record with an empty p= has been revoked.
DMARC: the record that makes the other two count
SPF and DKIM share a blind spot: neither looks at the From address the reader sees. SPF checks the envelope sender, also called the Return-Path, which bulk email services often set to their own domain. DKIM checks whichever domain did the signing. DMARC closes the gap with alignment: a message passes only if SPF or DKIM passes for a domain that matches the visible From domain. Under the default relaxed alignment, a subdomain such as mail.yourdomain.com counts as a match.
The p= tag tells receivers what to do with mail that fails. The safe rollout has three steps:
- Publish
v=DMARC1; p=none; rua=mailto:you@yourdomain.comand read the aggregate reports for a few weeks. They show which servers send as your domain to the providers that report, and whether each one passes. - Fix the legitimate sources that fail, usually by turning on DKIM signing with your own domain, or a custom return path, in each sending service.
- Move to
p=quarantine, optionally withpct=to apply it to a share of failing mail first, and then top=reject.
Since February 2024, Gmail and Yahoo have required bulk senders to publish SPF, DKIM and a DMARC record of at least p=none, with the From domain aligned to one of them. For Gmail, bulk means more than 5,000 messages a day to personal accounts. Microsoft announced similar rules for Outlook.com, Hotmail and Live addresses in 2025. Smaller senders are not off the hook: Gmail asks every sender to pass SPF or DKIM.
What a clean result does not tell you
Passing every check here means receivers can confirm that mail really comes from you. It does not guarantee the inbox. Reputation decides that: complaint and bounce rates, whether your sending IP or domain appears on a blocklist, how recipients engage, and the content itself. Reverse DNS for your sending servers, a working unsubscribe link and steady volume matter too. The guide to why emails go to spam works through those in the order worth checking them.

