Skip to content
Start with 100 free verification credits
Qualisend
Free tool

Email authentication checker.

Check a domain's SPF, DKIM, and DMARC records in one go — see which are published, whether DMARC is actually enforcing, and what each result means in plain language. The lookups run against live DNS. No account, no card.

DKIM keys live at selector._domainkey.yourdomain and DNS can't list them, so enter your selector if you know it. Otherwise we try common ones (google, default, selector1/2, k1, s1, mail, dkim).

What the three records prove

SPF, DKIM, and DMARC are the DNS records that let a receiving server decide whether a message really came from your domain. The full guide to email authentication walks through how they fit together; here's the short version:

SPF — who may send
A published list of the servers allowed to send mail for your domain. Missing SPF means receivers can't tell your senders from a spoofer's.
DKIM — a tamper-proof signature
A cryptographic signature on each message, verified against a public key at your selector. It proves the mail wasn't altered in transit.
DMARC — the policy and the reports
Tells receivers what to do with mail that fails SPF and DKIM, and sends you reports. See how to set up DMARC to move from monitoring to enforcement safely.

Why it matters for the inbox

Since 2024, Gmail and Yahoo require bulk senders to authenticate with SPF, DKIM, and an aligned DMARC record — mail that doesn't is throttled or rejected outright. The Google and Yahoo sender requirements spell out the full checklist. Authentication is necessary but not sufficient, though: passing records make you eligible for the inbox, while reputation, engagement, and a clean list are what actually get you delivered.

SPF, DKIM & DMARC checker — FAQ

Authenticated — now send to a clean list

SPF, DKIM, and DMARC prove your mail is genuine; verifying your list keeps bounces and spam traps from undoing that. Start free with 100 credits, no card required.

Start verifying