SPF RFC 7208
Sender Policy Framework is a TXT record listing the servers allowed to send mail with your domain. The receiver checks it against the envelope domain (Return-Path), not against the From the user sees.
More about SPF →Type your domain to see what it publishes, what is missing and how Gmail, Outlook, Yahoo and Apple will treat your mail. Starting from scratch? The generator gives you the exact records for your provider.
Try
Only the names looked up in public DNS leave your browser. Headers and reports are analysed on your device.
You will find them in the s= field of the DKIM-Signature header of an email you have sent.
Type your domain above. In a few seconds you get the grade, what is failing, how to fix it and the exact record to publish.
Who receives your mail and which service runs it: Microsoft 365, Google Workspace, a security gateway or your hosting company.
Syntax, the 10 DNS lookups the standard allows, void lookups, broken includes and IP ranges that are far too wide.
Looks for your keys across more than 60 common selectors, measures their length and spots broken CNAMEs or revoked keys.
Policy, subdomains, test mode, authorised report destinations and the RFC 9989 DNS tree walk.
Whether your DMARC allows the logo to show and which certificate each mailbox provider demands.
Whether you require encryption for the mail you receive and whether you will be told when encrypted delivery fails.
Whether your zone is signed and whether your mail servers publish TLSA records.
What Gmail, Yahoo, Outlook.com, Microsoft 365 and iCloud will do with your mail and with anyone trying to spoof you.
Choose who runs your mailboxes and which platforms send on your behalf. You get the records, their cost in SPF lookups, the steps in each panel and a phased DMARC plan.
Paste the headers of a message you received. You will see the route it took, what the receiving server checked and whether the sender is who they claim to be. They are analysed here, in your browser: they are not sent anywhere.
Drop in the aggregate reports that Google, Microsoft, Yahoo and others send you (XML, .xml.gz or .zip, several at once). I group the sources and tell you which ones are yours and fine, which need configuring and which are spoofing. The files never leave your device.
When a server receives a message claiming to come from your domain, it asks your DNS three questions. If the answers add up, the message passes; if not, your DMARC policy decides what happens. The complete email security guide walks through it step by step, with diagrams.
Sender Policy Framework is a TXT record listing the servers allowed to send mail with your domain. The receiver checks it against the envelope domain (Return-Path), not against the From the user sees.
More about SPF →DomainKeys Identified Mail is a cryptographic signature your server adds to each message. The receiver verifies it with the public key published in your DNS and knows whether the message changed on the way.
More about DKIM →DMARC requires SPF or DKIM to validate the same domain shown in the From (alignment), says what to do with anything that fails —nothing, spam or rejection— and sends you reports on who uses your domain.
More about DMARC →Brand Indicators for Message Identification shows your logo next to your messages in Gmail, Apple Mail, Yahoo and others. It needs DMARC at quarantine or reject and, for Gmail and Apple, a VMC or CMC certificate.
More about BIMI →Authenticated Received Chain is a chain of seals added by mailing lists and forwarders to vouch for how the message arrived. Gmail and Microsoft still use it, but the IETF proposes retiring it in favour of DKIM2.
More about ARC →MTA-STS forces servers sending you mail to encrypt the connection with a valid certificate. TLS-RPT sends you reports when that encrypted delivery fails. DANE does the same on top of DNSSEC.
More about encryption →I built it for the work I do with clients: understanding in ten minutes what is going on with a domain’s mail and what needs to change without breaking legitimate sending.
A prediction for Gmail, Yahoo, Outlook.com, Microsoft 365 and iCloud based on their published requirements: regular mail, bulk sending, spoofing and logo.
What the documentation of Microsoft 365, Google, IONOS, OVHcloud, Mailchimp, SendGrid or Amazon SES does not tell you, and how much each include costs.
Every include with its cost, the 10 lookups and the void lookups counted the way a receiver counts them, plus a test to see whether a specific IP passes.
Headers and DMARC reports are analysed in the browser. No uploading XML full of your providers’ IPs to someone else’s service.
RFC 9989 from May 2026: np, t, the DNS tree walk that replaces the Public Suffix List, the end of pct and the planned retirement of ARC.
Phased DMARC with dates, a warning when p=reject is not right for you and a PDF report for your team or your provider.
Values checked on 29 September 2026. “Lookups” is how many of SPF’s 10 lookups each include uses, counting the ones nested inside it.
| Provider | SPF include | Lookups | DKIM | Worth knowing |
|---|---|---|---|---|
| Microsoft 365 | spf.protection.outlook.com | 1 | 2 CNAME: selector1 and selector2 | It does not sign with your domain until you enable DKIM. The default key is 1024 bits: rotate it to 2048. |
| Google Workspace | _spf.google.com | 1 | TXT google._domainkey | Generate the 2048-bit key in the console and click “Start authentication”. |
| Zoho Mail | zoho.eu · zoho.com | 2 · 5 | TXT with the selector you choose | The include depends on your account’s data centre. |
| IONOS | _spf-eu.ionos.com | 1 | CNAME from the panel | If IONOS runs your DNS, DKIM is published as soon as you enable it. |
| OVHcloud | mx.ovh.com | 3 | 2 CNAME from the panel | Its include uses the ptr mechanism, which RFC 7208 discourages. |
| Hostinger | _spf.mail.hostinger.com | 3 | 3 CNAME hostingermail-a/b/c | It nests MailChannels’ SPF. |
| Proton Mail | _spf.protonmail.ch | 2 | 3 CNAME protonmail, protonmail2, protonmail3 | It also asks for a verification TXT record. |
| Fastmail | spf.messagingengine.com | 1 | 3 CNAME fm1, fm2, fm3 | It shows BIMI logos without requiring a certificate. |
| iCloud+ | icloud.com | 5 | CNAME sig1 | A single include eats half your SPF budget. |
| Platform | Include in your SPF? | DKIM | How it passes DMARC |
|---|---|---|---|
| Mailchimp | No: the Return-Path is theirs | 2 CNAME k2 and k3 | Through DKIM |
| Brevo | Not needed | 2 CNAME brevo1 and brevo2 | Through DKIM |
| Acumbamail | No | CNAME acumbamail | Through DKIM |
| SendGrid | No, with Automated Security | 2 CNAME s1 and s2 plus em#### | Through SPF and DKIM |
| Amazon SES | Not on the root domain | 3 CNAME Easy DKIM | Through DKIM; SPF with a custom MAIL FROM |
| Mailgun | On the sending subdomain (eu.mailgun.org, 2) | TXT on the subdomain | Through SPF and DKIM |
| Postmark | No | TXT plus CNAME pm-bounces | Through SPF and DKIM |
| HubSpot | Yes, your account’s own include | 2 CNAME hs1-… and hs2-… | Through DKIM |
| Zendesk | mail.zendesk.com (1) | 2 CNAME zendesk1 and zendesk2 | Through DKIM |
| Freshdesk | email.freshdesk.com (7) | CNAME from the panel | Through DKIM |
| Odoo online | _spf.odoo.com (3) | CNAME odoo | Through DKIM |
| Mimecast (gateway) | eu._netblocks.mimecast.com (1) | — | The global include costs 9 lookups |
Since 2024 the big mailbox providers stopped recommending and started requiring. This is what they ask for today, according to their official documentation.
| Mailbox | Applies to | Requires | If you fail |
|---|---|---|---|
| Gmail | All senders | SPF or DKIM, valid forward and reverse DNS, TLS, RFC 5322 format and a spam rate below 0.3%. | Temporary or permanent rejections, or the spam folder. |
| Gmail | More than 5,000 messages a day to personal accounts | SPF and DKIM, a published DMARC record (p=none is enough) aligned with SPF or DKIM, one-click unsubscribe (RFC 8058) and a spam rate below 0.3%. | Since November 2025, rejection with 5xx errors. |
| Yahoo and AOL | Bulk senders | SPF and DKIM, DMARC at p=none at least and aligned, one-click unsubscribe honoured within two days and a spam rate below 0.3%. | Filtering and rejection. |
| Outlook.com and Hotmail | More than 5,000 messages a day | Passing SPF and DKIM, and DMARC at p=none at least, aligned with SPF or DKIM. | Since 5 May 2025, “550 5.7.515” rejection. |
| Microsoft 365 as receiver | Mail arriving at businesses | It applies your domain’s p=quarantine and p=reject when “Honor DMARC policy” is on and summarises its decision in compauth. | Quarantine, Junk Email folder or rejection. |
| Apple iCloud Mail | Mail arriving at iCloud | It applies DMARC. To show BIMI it requires a VMC certificate. | No logo; quarantine or rejection depending on your policy. |
SPF publishes which servers may send with your domain and is checked against the envelope domain (Return-Path). DKIM signs each message and the receiver verifies the signature with a public key in your DNS. DMARC requires at least one of the two to validate the same domain shown in the From, says what to do with anything that fails and sends you reports.
Ten. The include, a, mx, ptr and exists mechanisms and the redirect modifier count, including those inside each include. If an evaluation needs more than ten, the result is permerror. RFC 7208 also recommends no more than two void lookups (names that do not exist or return nothing).
DKIM does not allow listing the published selectors: you can only ask for specific names. The tool tries more than 60 common selectors. If your provider uses another one, type it in the diagnosis options or look it up in the s= field of the DKIM-Signature header of one of your emails.
Not always. RFC 9989 asks you to go through p=none and p=quarantine for at least a month each first, requires DKIM signing from anyone publishing reject and discourages p=reject for domains whose users post to mailing lists. For domains that only send automated mail, or send no mail at all, reject is the right choice.
~all or -all?With DMARC enforced, ~all is what Google recommends, and RFC 9989 warns that with -all some receivers reject on SPF before looking at DMARC: you lose forwarded mail that DKIM would have saved, and those rejections never show up in your reports. -all is not wrong, but you should know about that effect. For domains that send no mail, always -all.
Only the names looked up in public DNS (for example, _dmarc.yourdomain.com), which the browser sends directly to Cloudflare’s resolver (1.1.1.1) using DNS over HTTPS. Headers and DMARC reports are analysed on your device and are not sent to any server.
Published in May 2026, it makes DMARC an IETF standard, replaces the Public Suffix List with a DNS tree walk, removes the pct, rf and ri tags, adds np (non-existent subdomains), t (test mode) and psd, and moves reporting into RFC 9990 and 9991.
No. BIMI only shows your logo in compatible mailboxes. It requires DMARC at quarantine or reject and, for Gmail, a VMC or CMC certificate; Apple Mail only accepts a VMC. Outlook does not show BIMI logos.
What leaves your browser
To read your records, the browser asks Cloudflare’s public DNS resolver (1.1.1.1) directly, using DNS over HTTPS. The names being looked up travel, such as _dmarc.yourdomain.com, and, as with any connection, your IP address. Those lookups do not go through my servers and I keep nothing. If you ask for the BIMI logo preview, your browser downloads it from the server named in the record. Headers and DMARC reports are processed on your device. More detail in the privacy policy.
StandardsRFC 7208 (SPF) · RFC 6376 (DKIM) · RFC 8301 · RFC 9989 (DMARC) · RFC 9990 · RFC 8617 (ARC) · RFC 7505 · RFC 8461 · RFC 8460 · RFC 7672 · RFC 8058
Mailbox providersGmail sender guidelines · Yahoo Sender Hub · Outlook.com requirements · Microsoft 365 anti-spam headers · BIMI in Apple Mail · BIMI Group
The score summarises a domain’s public configuration: it does not measure reputation, content or volume, which also decide delivery. Content reviewed on 29 September 2026.
I review your setup with your real providers, prepare the DMARC plan and see you through the move to quarantine and reject without losing legitimate mail.