Email authentication checker.
Check a domain's SPF, DKIM, and DMARC records in one go — see which are published, whether DMARC is actually enforcing, and what each result means in plain language. The lookups run against live DNS. No account, no card.
What the three records prove
SPF, DKIM, and DMARC are the DNS records that let a receiving server decide whether a message really came from your domain. The full guide to email authentication walks through how they fit together; here's the short version:
- SPF — who may send
- A published list of the servers allowed to send mail for your domain. Missing SPF means receivers can't tell your senders from a spoofer's.
- DKIM — a tamper-proof signature
- A cryptographic signature on each message, verified against a public key at your selector. It proves the mail wasn't altered in transit.
- DMARC — the policy and the reports
- Tells receivers what to do with mail that fails SPF and DKIM, and sends you reports. See how to set up DMARC to move from monitoring to enforcement safely.
Why it matters for the inbox
Since 2024, Gmail and Yahoo require bulk senders to authenticate with SPF, DKIM, and an aligned DMARC record — mail that doesn't is throttled or rejected outright. The Google and Yahoo sender requirements spell out the full checklist. Authentication is necessary but not sufficient, though: passing records make you eligible for the inbox, while reputation, engagement, and a clean list are what actually get you delivered.
SPF, DKIM & DMARC checker — FAQ
Authenticated — now send to a clean list
SPF, DKIM, and DMARC prove your mail is genuine; verifying your list keeps bounces and spam traps from undoing that. Start free with 100 credits, no card required.