Email Security Checker

SPF & DMARC Record Analyzer

ℹ️ About Email Security Checker
Enter a domain name to fetch, inspect, and evaluate its active SPF and DMARC configurations.

Resolving DNS records from Anycast servers...

🔒 SPF (Sender Policy Framework)

Active SPF TXT DNS Record:

Record Tags Breakdown:
Tag / Mechanism Description
⚠️
No SPF Record Found

Spammers can easily spoof emails using your domain. Generating a record is highly recommended.

🔑 DMARC Policy Status

Active DMARC TXT DNS Record:

Record Policy Explanations:
Parameter Description
⚠️
No DMARC Record Found

Without a DMARC policy, email operators cannot report or block phishing activities impersonating your brand.

🛠️ SPF Record Generator Wizard
Generated SPF DNS Record:
v=spf1 mx a ~all

Instructions: Add this as a TXT DNS record on your root domain host settings.

🛠️ DMARC Record Generator Wizard
Generated DMARC DNS Record:
v=DMARC1; p=none

Instructions: Add this as a TXT record for the host host named "_dmarc" on your DNS records.

Features

Why Check Email DNS Security?

Optimize your domain deliverability, secure mail verification nodes, and prevent address spoofing.

🔒

Prevent Email Spoofing

Protect your brand by ensuring hackers cannot forge emails using your active domain address.

📈

Boost Deliverability

Proper SPF and DMARC settings prevent your outgoing emails from getting flagged by spam filters.

🔍

Tag Breakdown

Read plain-text explanations for complex record tags (e.g. include, softfail, and reject policies).

🛠️

SPF Generator Wizard

Answer simple questions and let the wizard build a secure, validated SPF record automatically.

🔑

DMARC Policy Wizard

Easily define monitoring (none), quarantine, or reject DMARC policies for your domain.

📊

Anycast DNS Queries

Queries are resolved in real-time from active authoritative servers to bypass local network DNS caching.

FAQ

Frequently Asked Questions

Find quick answers to common questions regarding email security settings and DNS records.

SPF (Sender Policy Framework) is a DNS TXT record that lists all authorized servers permitted to send email on behalf of your domain.

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a protocol that uses SPF and DKIM to determine the authenticity of an email message and specifies action policies for failures.

Softfail (~all) tells receiving servers to flag unauthorized mail as suspicious but still deliver it, whereas Hardfail (-all) tells servers to reject unauthorized mail completely.

You must publish your DMARC record as a TXT DNS record with the host hostname set to "_dmarc.yourdomain.com".

SPF permits a maximum of 10 recursive DNS lookups (e.g. includes) to avoid DDoS attacks on DNS infrastructure. Exceeding this limit breaks SPF validation.
Do you accept cookies?

We use cookies to enhance your browsing experience. By using this site, you consent to our cookie policy.

Read Cookies
Loading chat...
Connecting to community chat.