Free SPF, DKIM, and DMARC checker
Enter your domain to check the public DNS records that help receiving mail systems verify your messages. See what passed, what needs attention, and what to fix first.
Check your domain's email authentication
Enter the part after the @ in your business email address. The scanner checks public SPF, DKIM, and DMARC records and returns a Wolferdawg diagnostic score out of 100.
- Free to use
- No account required
- No mailbox access
- No DNS changes
Example: enter example.com, not your full email address. Only public DNS records are checked.
What your email security results mean
The checker evaluates records published in public DNS. A pass means the expected record was found and met this tool's checks. It does not test a real email message.
| Check | What a pass means | Important limitation |
|---|---|---|
| SPF | A valid SPF record was found and the checker did not report a blocking issue. | A published SPF record does not prove every service that sends mail for you is authorized or aligned with DMARC. |
| DKIM | A DKIM record was found at one of the common selector names checked. | A failed lookup may mean your provider uses a custom selector. A found record does not prove every message is being signed. |
| DMARC record | A DMARC record was found at _dmarc.yourdomain.com and passed the tool's record checks. | A valid record can still be set to the monitoring-only p=none policy. |
| DMARC enforcement | The policy is p=quarantine or p=reject, which requests action when a message fails DMARC. | The receiving email system decides the final treatment, and legitimate senders can be affected if alignment was not tested first. |
What to fix first
- List every service that sends email using your domain. Include Microsoft 365 or Google Workspace, invoicing platforms, website forms, newsletters, and line-of-business applications.
- Correct SPF. Publish one SPF record that includes every approved sender and stays within the SPF lookup limit.
- Enable DKIM for each sending platform. DKIM lets the receiving system verify that an approved service signed the message.
- Publish DMARC with reporting. Start with p=none so you can identify legitimate and unauthorized sources without requesting that mail be blocked.
- Review the reports and fix alignment. Confirm that legitimate mail passes DMARC before increasing enforcement.
- Move gradually to p=quarantine and then p=reject. Continue monitoring after every change.
Want help fixing an email authentication problem?
Wolferdawg IT Consulting can identify every approved sending service, correct SPF and DKIM, and guide your DMARC policy toward enforcement without rushing changes that could affect legitimate email.
Book a 30-minute reviewHow this email security checker works
The scanner queries the public DNS system for your domain's SPF record, the DMARC record at _dmarc.yourdomain.com, and DKIM records under a list of common selectors. It evaluates the returned records and calculates a Wolferdawg diagnostic score.
The score assigns up to 40 raw points for SPF, 35 for DKIM, 35 for a DMARC record, and 60 for DMARC enforcement, then normalizes the total to 100. A p=none policy receives 15 enforcement points, p=quarantine receives 50, and p=reject receives 60.
Privacy and limitations
The checker reads public DNS records. It does not sign in to your email system, read messages, or change any DNS setting. For usage analytics, Wolferdawg records the submitted domain, score, SPF, DKIM and DMARC statuses, and detected DMARC policy.
The automated DKIM check tries common selector names. A failed DKIM lookup does not prove that DKIM is disabled because your sending service may use a custom selector. The checker also cannot confirm message-level SPF or DKIM alignment, inbox placement, or whether every legitimate sending service is configured correctly.
The 100-point result is a Wolferdawg diagnostic score, not an industry certification or a guarantee against spoofing. Microsoft recommends a gradual DMARC rollout that starts with p=none, moves to p=quarantine, and reaches p=reject after legitimate senders have been verified. Read Microsoft's DMARC guidance.
Reviewed by Dieter Wolf, founder of Wolferdawg IT Consulting
27+ years in IT and cybersecurity. Last updated August 25, 2026.
More free email security tools
Build a new authentication record or learn how the pieces fit together.
Email security checker common questions
Short answers about what the checker tests and how to read the results.
What does this email security checker check?
The checker looks up the public SPF and DMARC records for your domain and searches common DKIM selectors used by Microsoft 365, Google Workspace, and other mail platforms. It reports what was found, evaluates DMARC enforcement, and calculates a Wolferdawg diagnostic score out of 100.
Is it safe to enter my domain?
Yes. The checker reads DNS records that are already public. It does not sign in to your email, read messages, or change DNS. For usage analytics, Wolferdawg records the submitted domain, score, SPF, DKIM and DMARC statuses, and detected DMARC policy.
Why is my score low when SPF and DKIM pass?
SPF and DKIM authenticate parts of a message, but DMARC checks whether those authenticated domains align with the address people see in the From field. The checker gives more weight to DMARC enforcement, so a missing DMARC record or a monitoring-only p=none policy lowers the score.
What does it mean when DMARC enforcement fails?
The check fails when no DMARC record is found, the policy is p=none, or the policy cannot be identified. A p=none policy is useful for monitoring, but it does not ask receiving systems to apply a DMARC-specific quarantine or rejection. Move gradually to p=quarantine or p=reject only after confirming that legitimate senders pass DMARC.
Does a missing DKIM result prove DKIM is disabled?
No. DKIM records use selector names chosen by the sending platform. The checker tries common selectors, including selector1 and selector2 for Microsoft 365 and google for Google Workspace. Your domain may use a custom selector that the automated scan cannot discover.
Does a score of 100 guarantee email delivery or stop all spoofing?
No. The score evaluates public DNS configuration, not every message your company sends. It cannot confirm that every approved service signs and aligns its mail, guarantee inbox placement, or replace DMARC report review and message-header testing.
How is the email security score calculated?
The Wolferdawg diagnostic score assigns up to 40 raw points for SPF, 35 for DKIM, 35 for a DMARC record, and 60 for DMARC enforcement, then normalizes the result to 100. A p=none policy receives 15 enforcement points, p=quarantine receives 50, and p=reject receives 60. This is a diagnostic score, not an industry certification.