Skip to content

Domain Health Checker

Audit the DNS and email trust records that affect deliverability, security and domain reputation.

Optional. Leave it empty and we will probe common selectors automatically (default, google, selector1...).

What is checked

The checker reads public DNS records and reports whether the domain has mail routing, SPF and DMARC protection, optional DKIM, nameservers and IPv6.

How the recipient verifies an email

How the recipient verifies an email with SPF, DKIM and DMARC The receiving server checks the SPF record of the envelope domain (MAIL FROM), the DKIM key and the DMARC policy of the From domain, one after another. A genuine email passes every check, a spoofed one fails and gets rejected. Sender 203.0.113.7 Attacker 198.51.100.66 DNS yourdomain.com SPF 203.0.113.7 DKIM key DMARC p=reject Recipient SPF DKIM DMARC Accepted ✓ Rejected ✕

The server of yourdomain.com with the IP address 203.0.113.7 sends an email. yourdomain.com is both on the envelope (SMTP MAIL FROM) and in the visible From field, and the message is signed with a DKIM seal.

The recipient takes the envelope domain (MAIL FROM) and checks its SPF record to see whether 203.0.113.7 is allowed to send its mail. It is on the list, so SPF passes.

It fetches the public key from DNS and uses it to verify the signature. The signature matches, so nobody changed the signed headers or the message body on the way.

DMARC checks that the domain SPF or DKIM passed for matches the domain in the visible From field. It matches, so the recipient accepts the message. Whether it lands in the inbox or in spam is still up to other filters.

An attacker sends an email from their own server and puts an address at yourdomain.com both on the envelope (MAIL FROM) and in the From field. They have no valid signature for the domain.

The IP address 198.51.100.66 is not in the SPF record of yourdomain.com. SPF fails.

The message has no signature that could be verified with the key from DNS. DKIM fails.

Neither SPF nor DKIM passed. Even if the attacker used their own domain on the envelope and SPF passed, it would not match the From field. The DMARC record says p=reject, so the recipient rejects the message.

Useful for

  • Checking email spoofing protection
  • Auditing a new business domain
  • Debugging missing SPF or DMARC
  • Reviewing DNS before a website launch

How to read the score

The score summarizes the most important public DNS and email trust signals. MX, SPF and DMARC matter most because they affect mail routing, deliverability and sender spoofing protection. IPv6 and nameservers add context about technical readiness.

  • MX records tell the internet where email for the domain should be delivered.
  • SPF lists the servers allowed to send email for the domain.
  • DMARC tells receivers what to do when authentication fails.
  • DKIM signs outgoing email, but checking it requires the correct selector.

What to fix first

For a business domain, fix missing MX, SPF and DMARC first. Without them, deliverability can suffer and attackers may spoof your domain more easily. Configure DKIM with your mail provider because selector names differ between services.

  • Missing MX usually means the domain cannot receive email.
  • Missing SPF makes it harder to verify sending servers.
  • Missing DMARC weakens spoofing and phishing protection.
  • Failing DKIM usually means the selector or public key is wrong.

Limitations

The checker reads public DNS records. It cannot prove whether a specific email will pass a spam filter or whether your mail provider has every internal setting configured correctly.

  • DKIM can only be checked when you know the selector.
  • DNS changes may take time to propagate because of TTL caching.
  • The score does not replace a real email delivery test.
  • The tool cannot inspect private provider settings.

FAQ

Is DMARC required?

It is not always legally required, but it is strongly recommended for business domains. DMARC helps protect your brand from phishing and tells receivers how to handle suspicious messages.

Which DKIM selector should I use?

Find the selector in your email provider settings. Common values include default, google, selector1 and selector2, but every provider can use a different name.

Is SPF enough without DMARC?

SPF is important, but it is not enough on its own. DMARC combines SPF and DKIM into a policy that receivers can enforce.

Why is a DNS change not visible yet?

DNS records are cached according to their TTL. It can take minutes or hours before all resolvers see the new value.