Everything our two free tools check, and why each one matters

Email authentication fails quietly. There is no error message when a DNS record is wrong. Mail just starts landing in spam, or a stranger starts sending as you, and nobody notices for weeks.
We built two free tools to make those problems visible before they cost you anything. Both are free, need no account, and work in English and French.
- The domain checker reads your domain's DNS records and grades them.
- The email tester gives you an address; you send one real email to it, and it grades what actually arrived.
Used our checker or email tester before September 29, 2026? Run them again. Both tools now check a lot more than they did, and a domain that passed before may not pass today.
Use the checker first. Then send one real message to the tester, because DNS tells you what should happen and a received message tells you what did.
Read the way a receiver reads
Two principles sit under every check below.
We ask your domain's own DNS servers. Public resolvers keep copies of records for a while. If you fix something and check right away, a cached answer shows you the old record. Ours reads the live one, so a fix shows up immediately.
We read every record the way a receiving mail server does. A receiver does not skip the parts it does not understand. One wrong character can make it ignore a whole record, so we check every term, name the one that is wrong, and show your record exactly as you published it.
The domain checker
DMARC: the instruction to the world
DMARC tells receiving servers what to do with mail that fails authentication. It is the control that actually stops someone from sending as your domain, so it carries the most weight in your grade.
- Your real policy, not just the
p=tag.p=rejectwithpct=10, or witht=y, or with weaker subdomain rules (sp=,np=) does not protect what it seems to. We score what the record actually enforces. - Errors that make receivers ignore the record: a misspelled policy (
p=rejctis treated asp=none),v=DMARC1not at the start, two DMARC records on one domain. - Reports that go nowhere: a report address without
mailto:, or reports sent to a provider that has not authorised receiving them. - Tags that are silently ignored: misspellings, duplicates, invalid values.
SPF: the guest list
SPF lists the servers allowed to send as your domain.
- Syntax, term by term. A colon where an equals sign belongs (
redirect:instead ofredirect=), a misspelled term, an invalid IP address: any one of them makes receivers reject the whole record. We name it and show the correct spelling. - The 10-lookup limit. Every
include:can hide more includes. We follow all of them and show the count (7/10 DNS lookups used), with a warning at 9, before one more service breaks SPF for all your mail. - Includes that point at nothing, or at a record that is itself broken.
- Dead names in
a:andmx:entries. Receivers tolerate two; the third breaks SPF. - Parts that never run: a
redirect=ignored because the record ends inall, and anything written afterall. - How the record ends:
-all,~all, the ineffective?all, and the dangerous+all, which lets anyone send as you.
The rest of your mail setup
- MX: where your mail is received, and whether you have a backup.
- DNSSEC: whether your DNS answers are signed, so they cannot be forged on the way.
- MTA-STS and TLS-RPT: whether other servers must use encryption to deliver to you, and whether you receive reports when that fails.
- BIMI: whether your logo is published for mail clients that show one. Shown for information only; it never lowers your grade.
You get an A–F grade out of 100, the issues in priority order, and a plain-language fix for each one.
The email tester
The checker sees your records. The tester sees your mail. Send one message to the address it gives you, from the account you normally use, and it reports on that exact message.
- SPF, DKIM and DMARC for this message: did the server that sent it pass, and does the result line up with the address your recipients see?
- DKIM in detail: which signature failed, and why. The published key does not match the one your server signs with, the message was changed after it was signed, or the key record is missing. We name the exact DNS record to fix.
- Your whole domain, checked at the same time: the same DMARC, SPF, MX, DNSSEC, MTA-STS and TLS-RPT checks as above, including the lookup count.
- A report you can share. The link stays valid for seven days, so you can send it to whoever manages your DNS.
Five minutes, in this order
- Run your domain through the checker.
- Send one real email to the tester from the account you use every day.
- Fix the first red line first. Errors mean receivers ignore the record; warnings can wait a week.
- Check again after every DNS change, including the ones made for other reasons. A new newsletter tool is the classic way to break SPF.
Pass it on
Whoever manages your DNS will not get an error message when a record goes wrong. Send them the free checker. It takes ten seconds.
Want to read this later? Email it to yourself.
Stay ahead of email threats
Get our latest DMARC, SPF, and email-security guides in your inbox. No spam — unsubscribe anytime.
We only use your email to send blog updates. One click unsubscribes you.