Why email authentication matters
Without authentication, anyone can forge email that appears to come from your domain. SPF, DKIM and DMARC work together to prove a message is genuine and tell receivers how to handle fakes, protecting your brand and improving deliverability.
What this tool checks
- SPF: the
v=spf1 TXT record on your domain listing authorised senders. - DMARC: the
v=DMARC1 TXT record at _dmarc.yourdomain defining your enforcement policy.
DKIM uses a selector that varies per provider, so it isn't auto-discoverable here, so check your email provider's docs for your DKIM selector.
Related tools
See where mail is delivered with MX Lookup, or inspect all records with DNS Lookup.
Frequently asked questions
What is an SPF record?
SPF (Sender Policy Framework) is a TXT record listing which mail servers are allowed to send email for your domain. Receiving servers use it to detect forged senders.
What is a DMARC record?
DMARC builds on SPF and DKIM. It's a TXT record at _dmarc.yourdomain that tells receivers what to do with messages that fail authentication (none, quarantine, or reject) and where to send reports.
Do I need both SPF and DMARC?
Yes. Together with DKIM, they make up modern email authentication. SPF and DKIM verify the sender, while DMARC enforces a policy and gives you visibility. Missing records make your domain easier to spoof.
What does a good DMARC policy look like?
Start with p=none to monitor, then move to p=quarantine and ideally p=reject once you've confirmed legitimate mail passes. Always include a rua= address to receive aggregate reports.