Audit tool

Inspect SPF, DKIM, and DMARC for any domain.

Email authentication is configured entirely in DNS. Enter a domain and we look up its SPF, DKIM, and DMARC records via DNS-over-HTTPS, resolve recursive include: chains, and surface the configuration issues that affect deliverability and spoofing resistance. No backend, no rate limit tricks — only public DoH endpoints from Google and Cloudflare.

Domain

The apex domain. Subdomains are checked via DKIM selector and DMARC records.

We look up <selector>._domainkey.<domain>. Common selectors: default, google, selector1, k1.

Both providers return the same records; switch if one is blocked by your network.

No check has been run yet.

How this checker works

Background on the three records and the heuristics applied to each.

SPF

We look up the apex TXT record, then walk every include: chain recursively (capped at 10 levels to avoid loops) and total the DNS lookups. +all and no policy at all are the dangerous cases.

DKIM

We query <selector>._domainkey.<domain>, parse the p= tag, and report the key length. Anything below 1024 bits is considered weak by modern receivers.

DMARC

We parse p, sp, pct, rua, ruf, adkim, and aspf. A policy of none means receivers will not act on failures — emails can still be spoofed.