Home Tools SPF, DKIM & DMARC

Check and set up your domain’s SPF, DKIM, DMARC and BIMI

Type your domain to see what it publishes, what is missing and how Gmail, Outlook, Yahoo and Apple will treat your mail. Starting from scratch? The generator gives you the exact records for your provider.

Try

Only the names looked up in public DNS leave your browser. Headers and reports are analysed on your device.

SPF · DKIM · DMARC BIMI · ARC MTA-STS · DANE RFC 9989 No sign-up
Journey of an authenticated email Your mail program hands the message to your server, which signs it with DKIM. The recipient’s server looks up SPF, DKIM and DMARC in your domain’s DNS and, if everything checks out, delivers it to the inbox with the BIMI logo. Your domain’s DNS SPF · IP authorised DKIM · valid signature DMARC · aligned YouMUA Your serverMSA · MTA Their serverMX · MTA InboxMDA · MUA
The receiver asks your DNS before deciding.

Options: your own DKIM selectors

You will find them in the s= field of the DKIM-Signature header of an email you have sent.

What it checks

Eight checks in a single lookup

Type your domain above. In a few seconds you get the grade, what is failing, how to fix it and the exact record to publish.

  • MX and provider

    Who receives your mail and which service runs it: Microsoft 365, Google Workspace, a security gateway or your hosting company.

  • SPF

    Syntax, the 10 DNS lookups the standard allows, void lookups, broken includes and IP ranges that are far too wide.

  • DKIM

    Looks for your keys across more than 60 common selectors, measures their length and spots broken CNAMEs or revoked keys.

  • DMARC

    Policy, subdomains, test mode, authorised report destinations and the RFC 9989 DNS tree walk.

  • BIMI

    Whether your DMARC allows the logo to show and which certificate each mailbox provider demands.

  • MTA-STS and TLS-RPT

    Whether you require encryption for the mail you receive and whether you will be told when encrypted delivery fails.

  • DNSSEC and DANE

    Whether your zone is signed and whether your mail servers publish TLSA records.

  • How they will see you

    What Gmail, Yahoo, Outlook.com, Microsoft 365 and iCloud will do with your mail and with anyone trying to spoof you.

In 30 seconds

How an email gets authenticated

When a server receives a message claiming to come from your domain, it asks your DNS three questions. If the answers add up, the message passes; if not, your DMARC policy decides what happens. The complete email security guide walks through it step by step, with diagrams.

SPF RFC 7208

Sender Policy Framework is a TXT record listing the servers allowed to send mail with your domain. The receiver checks it against the envelope domain (Return-Path), not against the From the user sees.

More about SPF →

DKIM RFC 6376

DomainKeys Identified Mail is a cryptographic signature your server adds to each message. The receiver verifies it with the public key published in your DNS and knows whether the message changed on the way.

More about DKIM →

DMARC RFC 9989

DMARC requires SPF or DKIM to validate the same domain shown in the From (alignment), says what to do with anything that fails —nothing, spam or rejection— and sends you reports on who uses your domain.

More about DMARC →

BIMI IETF draft

Brand Indicators for Message Identification shows your logo next to your messages in Gmail, Apple Mail, Yahoo and others. It needs DMARC at quarantine or reject and, for Gmail and Apple, a VMC or CMC certificate.

More about BIMI →

ARC RFC 8617

Authenticated Received Chain is a chain of seals added by mailing lists and forwarders to vouch for how the message arrived. Gmail and Microsoft still use it, but the IETF proposes retiring it in favour of DKIM2.

More about ARC →

MTA-STS and TLS-RPT RFC 8461 · 8460

MTA-STS forces servers sending you mail to encrypt the connection with a valid certificate. TLS-RPT sends you reports when that encrypted delivery fails. DANE does the same on top of DNSSEC.

More about encryption →
Why another tool

What you will not find in other checkers

I built it for the work I do with clients: understanding in ten minutes what is going on with a domain’s mail and what needs to change without breaking legitimate sending.

How the big mailbox providers will see you

A prediction for Gmail, Yahoo, Outlook.com, Microsoft 365 and iCloud based on their published requirements: regular mail, bulk sending, spoofing and logo.

Provider know-how

What the documentation of Microsoft 365, Google, IONOS, OVHcloud, Mailchimp, SendGrid or Amazon SES does not tell you, and how much each include costs.

The full SPF tree

Every include with its cost, the 10 lookups and the void lookups counted the way a receiver counts them, plus a test to see whether a specific IP passes.

Your mail never leaves your device

Headers and DMARC reports are analysed in the browser. No uploading XML full of your providers’ IPs to someone else’s service.

Up to date with DMARCbis

RFC 9989 from May 2026: np, t, the DNS tree walk that replaces the Public Suffix List, the end of pct and the planned retirement of ARC.

A plan, not just a record

Phased DMARC with dates, a warning when p=reject is not right for you and a PDF report for your team or your provider.

Cheat sheet

Records by email provider

Values checked on 29 September 2026. “Lookups” is how many of SPF’s 10 lookups each include uses, counting the ones nested inside it.

Mailbox providers
ProviderSPF includeLookupsDKIMWorth knowing
Microsoft 365spf.protection.outlook.com12 CNAME: selector1 and selector2It does not sign with your domain until you enable DKIM. The default key is 1024 bits: rotate it to 2048.
Google Workspace_spf.google.com1TXT google._domainkeyGenerate the 2048-bit key in the console and click “Start authentication”.
Zoho Mailzoho.eu · zoho.com2 · 5TXT with the selector you chooseThe include depends on your account’s data centre.
IONOS_spf-eu.ionos.com1CNAME from the panelIf IONOS runs your DNS, DKIM is published as soon as you enable it.
OVHcloudmx.ovh.com32 CNAME from the panelIts include uses the ptr mechanism, which RFC 7208 discourages.
Hostinger_spf.mail.hostinger.com33 CNAME hostingermail-a/b/cIt nests MailChannels’ SPF.
Proton Mail_spf.protonmail.ch23 CNAME protonmail, protonmail2, protonmail3It also asks for a verification TXT record.
Fastmailspf.messagingengine.com13 CNAME fm1, fm2, fm3It shows BIMI logos without requiring a certificate.
iCloud+icloud.com5CNAME sig1A single include eats half your SPF budget.
Platforms that send on your behalf
PlatformInclude in your SPF?DKIMHow it passes DMARC
MailchimpNo: the Return-Path is theirs2 CNAME k2 and k3Through DKIM
BrevoNot needed2 CNAME brevo1 and brevo2Through DKIM
AcumbamailNoCNAME acumbamailThrough DKIM
SendGridNo, with Automated Security2 CNAME s1 and s2 plus em####Through SPF and DKIM
Amazon SESNot on the root domain3 CNAME Easy DKIMThrough DKIM; SPF with a custom MAIL FROM
MailgunOn the sending subdomain (eu.mailgun.org, 2)TXT on the subdomainThrough SPF and DKIM
PostmarkNoTXT plus CNAME pm-bouncesThrough SPF and DKIM
HubSpotYes, your account’s own include2 CNAME hs1-… and hs2-…Through DKIM
Zendeskmail.zendesk.com (1)2 CNAME zendesk1 and zendesk2Through DKIM
Freshdeskemail.freshdesk.com (7)CNAME from the panelThrough DKIM
Odoo online_spf.odoo.com (3)CNAME odooThrough DKIM
Mimecast (gateway)eu._netblocks.mimecast.com (1)—The global include costs 9 lookups
What they require

Gmail, Yahoo and Microsoft requirements

Since 2024 the big mailbox providers stopped recommending and started requiring. This is what they ask for today, according to their official documentation.

MailboxApplies toRequiresIf you fail
GmailAll sendersSPF or DKIM, valid forward and reverse DNS, TLS, RFC 5322 format and a spam rate below 0.3%.Temporary or permanent rejections, or the spam folder.
GmailMore than 5,000 messages a day to personal accountsSPF and DKIM, a published DMARC record (p=none is enough) aligned with SPF or DKIM, one-click unsubscribe (RFC 8058) and a spam rate below 0.3%.Since November 2025, rejection with 5xx errors.
Yahoo and AOLBulk sendersSPF and DKIM, DMARC at p=none at least and aligned, one-click unsubscribe honoured within two days and a spam rate below 0.3%.Filtering and rejection.
Outlook.com and HotmailMore than 5,000 messages a dayPassing SPF and DKIM, and DMARC at p=none at least, aligned with SPF or DKIM.Since 5 May 2025, “550 5.7.515” rejection.
Microsoft 365 as receiverMail arriving at businessesIt applies your domain’s p=quarantine and p=reject when “Honor DMARC policy” is on and summarises its decision in compauth.Quarantine, Junk Email folder or rejection.
Apple iCloud MailMail arriving at iCloudIt applies DMARC. To show BIMI it requires a VMC certificate.No logo; quarantine or rejection depending on your policy.
No small print

Frequently asked questions

What is the difference between SPF, DKIM and DMARC?

SPF publishes which servers may send with your domain and is checked against the envelope domain (Return-Path). DKIM signs each message and the receiver verifies the signature with a public key in your DNS. DMARC requires at least one of the two to validate the same domain shown in the From, says what to do with anything that fails and sends you reports.

How many DNS lookups can an SPF record have?

Ten. The include, a, mx, ptr and exists mechanisms and the redirect modifier count, including those inside each include. If an evaluation needs more than ten, the result is permerror. RFC 7208 also recommends no more than two void lookups (names that do not exist or return nothing).

Why can the tool not find my DKIM key?

DKIM does not allow listing the published selectors: you can only ask for specific names. The tool tries more than 60 common selectors. If your provider uses another one, type it in the diagnosis options or look it up in the s= field of the DKIM-Signature header of one of your emails.

Do I have to publish DMARC with p=reject?

Not always. RFC 9989 asks you to go through p=none and p=quarantine for at least a month each first, requires DKIM signing from anyone publishing reject and discourages p=reject for domains whose users post to mailing lists. For domains that only send automated mail, or send no mail at all, reject is the right choice.

Is it better to end SPF with ~all or -all?

With DMARC enforced, ~all is what Google recommends, and RFC 9989 warns that with -all some receivers reject on SPF before looking at DMARC: you lose forwarded mail that DKIM would have saved, and those rejections never show up in your reports. -all is not wrong, but you should know about that effect. For domains that send no mail, always -all.

What data leaves my browser when I use the tool?

Only the names looked up in public DNS (for example, _dmarc.yourdomain.com), which the browser sends directly to Cloudflare’s resolver (1.1.1.1) using DNS over HTTPS. Headers and DMARC reports are analysed on your device and are not sent to any server.

What changes with DMARCbis (RFC 9989)?

Published in May 2026, it makes DMARC an IETF standard, replaces the Public Suffix List with a DNS tree walk, removes the pct, rf and ri tags, adds np (non-existent subdomains), t (test mode) and psd, and moves reporting into RFC 9990 and 9991.

Do I need BIMI for my mail to be delivered?

No. BIMI only shows your logo in compatible mailboxes. It requires DMARC at quarantine or reject and, for Gmail, a VMC or CMC certificate; Apple Mail only accepts a VMC. Outlook does not show BIMI logos.

What leaves your browser

To read your records, the browser asks Cloudflare’s public DNS resolver (1.1.1.1) directly, using DNS over HTTPS. The names being looked up travel, such as _dmarc.yourdomain.com, and, as with any connection, your IP address. Those lookups do not go through my servers and I keep nothing. If you ask for the BIMI logo preview, your browser downloads it from the server named in the record. Headers and DMARC reports are processed on your device. More detail in the privacy policy.

Sources and method

StandardsRFC 7208 (SPF) · RFC 6376 (DKIM) · RFC 8301 · RFC 9989 (DMARC) · RFC 9990 · RFC 8617 (ARC) · RFC 7505 · RFC 8461 · RFC 8460 · RFC 7672 · RFC 8058

Mailbox providersGmail sender guidelines · Yahoo Sender Hub · Outlook.com requirements · Microsoft 365 anti-spam headers · BIMI in Apple Mail · BIMI Group

The score summarises a domain’s public configuration: it does not measure reputation, content or volume, which also decide delivery. Content reviewed on 29 September 2026.

Shall we review it together?

I review your setup with your real providers, prepare the DMARC plan and see you through the move to quarantine and reject without losing legitimate mail.