Email DNS Checker

Inspect SPF lookup chains, DKIM public keys, DMARC policy and MX records. Get a transparent DNS configuration score and practical diagnostics.

Runs in your browser

Queries public DNS after a short input delay. Headers stay in this tab; only the domain and selectors are queried. This does not verify a message signature or guarantee delivery.

After a short input delay, your browser queries the selected resolver with the domain and DKIM selectors. The resolver sees your public IP. Pasted headers remain in this tab.

Separate selectors with commas or spaces. Pasted headers stay in this tab only.

Score

Score
Enter a domain to inspect SPF, DKIM, DMARC and MX.

SPF lookup budget

SPF mechanisms such as include, a, mx, exists and redirect can cause DNS lookups. Nested includes count toward the limit. The tree identifies repeated branches and loops; macros and sender-dependent evaluation limit what a static inspection can conclude.

DKIM selectors and public keys

A selector identifies a key at selector._domainkey.example.com. DNS does not provide a complete selector directory. Enter the selector from a real message for a reliable lookup. Finding a key does not verify the signature of that message.

DMARC policy and alignment

DMARC connects the visible From domain with authenticated SPF or DKIM identifiers. p=none monitors, while quarantine and reject request stronger receiver handling. Deploy enforcement only after checking legitimate senders and aggregate reports.

MX and optional mail policies

MX priorities rank mail servers. A single 0 . record is Null MX and means no inbound email is accepted. Optional BIMI, MTA-STS and TLS-RPT DNS records add policy information, but their existence alone does not prove that logos, HTTPS policies or TLS delivery work.

Interpret the score carefully

The score summarizes DNS configuration checks and excludes unavailable sections. It is not a deliverability score, an inbox-placement prediction or a complete security audit. Organizational-domain fallback uses a bounded suffix list, so uncommon public suffixes need manual verification.

How to use

  1. Enter your email domain or paste a DKIM-Signature header to extract its domain and selector.
  2. Add known DKIM selectors and choose a resolver.
  3. Review SPF lookup counts, DKIM key details, DMARC policy and MX results.
  4. Read each diagnostic before changing DNS, and copy the summary for follow-up.

FAQ

Can this find every DKIM selector?

No. Common names can be probed, but use the s= selector from an actual DKIM-Signature header.

Does a perfect score guarantee delivery?

No. Reputation, content, authentication alignment and receiver policy also affect delivery.

Are pasted message headers uploaded?

The header stays in this tab. Extracted domains and selectors are sent as DNS queries to the selected resolver, which also sees your public IP.

Why can a section be unavailable?

A request can time out or be blocked. Unavailable data is not treated as a missing or invalid DNS record.

Related tools

More Internet tools: Internet

Send feedback

Found a bug or have an idea? Tell us — it helps make the tools better.

Only needed if you would like a reply.

Page: /internet/email-dns-checker/