If your emails end up in spam or attackers are sending messages impersonating your domain, the root cause is almost always missing or broken email authentication. SPF, DKIM, and DMARC are TXT records published in DNS that tell receiving mail servers who is authorised to send on your behalf — and what to do with messages that fail verification. Without them, your domain is open to spoofing and your deliverability will suffer.
How to use the tool
Enter a domain name in the field above and click "Check". The tool queries DNS in real time and displays:
- the current SPF record and whether it is present;
- the DMARC policy and the protection level it enforces;
- the policy value (none, quarantine, or reject).
No registration required. Results appear instantly for any domain.
Understanding the results
SPF (Sender Policy Framework) lists the IP addresses and mail servers authorised to send email for your domain. A missing or misconfigured SPF record is one of the most common reasons legitimate emails are marked as spam.
The DMARC policy tells the receiving server what to do with messages that fail SPF or DKIM checks:
none— monitoring only; messages are delivered regardless;quarantine— suspicious messages are routed to the spam folder;reject— unauthenticated messages are refused outright.
Frequently asked questions
Why do my emails go to spam even though SPF is set up?
SPF is only one piece of the puzzle. If DMARC is absent or set to none and DKIM is not configured, major providers like Gmail and Outlook may still penalise your sender reputation. Full protection requires all three mechanisms working together.
What does DMARC policy "reject" mean, and is it safe to enable?
The reject policy is the strictest level: messages that fail SPF or DKIM are refused by the recipient's server and never delivered. It provides strong anti-spoofing protection, but requires preparation — every legitimate mail stream must be properly authenticated first, or real emails will be blocked.
How is SPF different from DKIM?
SPF validates the sending server's IP address, while DKIM uses a cryptographic signature to verify the message content. They complement each other: SPF can break when an email is forwarded, whereas the DKIM signature travels with the message and remains intact.
Can I check DKIM without knowing the selector?
There is no standard public method for guessing selectors — they are configured manually by your email service provider. If you do not know your selector, check the DNS zone of your domain or look it up in the control panel of your ESP (Google Workspace, Mailchimp, SendGrid, etc.).
For a complete DNS infrastructure check, use the DNS record lookup tool or explore all available tools on the platform.