Free network tool

Email DNS checker (SPF, DKIM, DMARC)

Look up a domain’s SPF, DMARC, and DKIM records — the email-authentication settings receiving servers check to keep your mail out of spam. SPF and DMARC are automatic; DKIM takes a selector. Nothing stored.

Check a domain’s email authentication DNS records — SPF, DMARC, and (with a selector) DKIM. These are what receiving mail servers check to decide whether your mail is trustworthy, so missing or broken records are a common reason legitimate email lands in spam. Nothing is stored.

SPF and DMARC are found automatically. DKIM needs the selector your mail provider uses (e.g. google, s1, selector1) — it’s in your DKIM setup or a message’s headers.

What these records do

SPF (Sender Policy Framework) lists which servers are allowed to send mail for your domain. DKIM (DomainKeys Identified Mail) adds a cryptographic signature so a receiver can confirm a message wasn’t altered and really came from you. DMARC ties the two together and tells receivers what to do with mail that fails — nothing, quarantine, or reject. Together they’re the backbone of email deliverability and anti-spoofing.

Why DKIM needs a selector

SPF and DMARC live at predictable names (yourdomain.com and _dmarc.yourdomain.com), so we can look them up from the domain alone. DKIM is different: its record lives at <selector>._domainkey.yourdomain.com, and there’s no way to discover the selector through DNS — you have to know it. If a DKIM lookup comes back empty, it usually means the selector is wrong, not that DKIM is missing. You can find your selector in your email provider’s DKIM settings, or in the DKIM-Signature header of a message you’ve sent (the s= value).

Related: Reverse DNS (FCrDNS) check · Blacklist check · SPF, DKIM, DMARC & rDNS explained

0 IPs logged or stored
2 stacks shown (v4 & v6)
8+ diagnostic tools
lookups, always free