SPF and DMARC checker
Look up the SPF, DMARC, MTA-STS and CAA records of a domain online and see how each one is rated. Enter the domain you send mail from, for example example.com rather than www.example.com.
Validating the public target…
—
The mail DNS check is open first, including its MTA-STS and CAA rows. The other seven passive checks from the same run are listed below it, closed.
Values are shortened and sanitized: IP addresses, cookie values, tokens and the name part of e-mail addresses are removed, and URLs are reduced to scheme and host.
Let your coding agent fix it, then re-test.
Carry this target into Sitelemetry, connect Codex or Claude, generate a bounded fix prompt and run the same checks again.
What each record does and how it is rated
The checker reads these records on the hostname you enter. Missing SPF, DMARC and MTA-STS records are flagged only when the host has MX records, because a host that receives no mail does not need them in the same way.
| Record | Where it is published | What good looks like | How this checker rates it |
|---|---|---|---|
MX | MX records on the hostname. | Present on domains that receive mail. | Counted and shown; never a finding on its own. |
SPF | A TXT record starting v=spf1 on the hostname. | Exactly one SPF record that lists every service sending mail for the domain. | Missing while the host has MX records: medium. The record text is shown. |
| SPF all mechanism | The last term of the SPF record. | -all or ~all. | +all: high. ?all: low. -all and ~all raise nothing. |
| SPF DNS lookups | The include, a, mx, ptr, exists and redirect terms of the record. | At most ten terms that need a DNS lookup. | More than ten in the top-level record: medium. include: targets are not expanded, so nested lookups are not counted. |
DMARC | A TXT record starting v=DMARC1 at _dmarc.example.com for example.com. | p=quarantine or p=reject once reports show that all legitimate mail passes. | Missing while the host has MX records: medium. p=none: low. quarantine or reject: passed. sp, pct, rua and alignment are not evaluated. On a subdomain, receivers also apply the organizational domain’s DMARC policy, which this check does not read. |
MTA-STS | A TXT record starting v=STSv1 at _mta-sts.example.com, plus a policy file on the mta-sts host. | Both the record and the policy file, in enforce mode once tested. | Missing record while the host has MX records: low. Only the DNS record is checked; the policy file is not fetched. |
CAA | CAA records on the hostname. | Records that name only the certificate authorities you use. | Any CAA record: passed. None: low. The contents are not compared with your certificate. On a subdomain, certificate authorities also honour the parent domain’s CAA, which this check does not read. |
DKIM | TXT records at selector._domainkey.example.com. | A key for each service that signs your mail. | Not checked: selector names cannot be discovered from DNS alone. |
TLS reporting, DNSSEC and BIMI are not checked.
How to read each status.
- 01PassedThe record was found and meets the check.
- 02Low · Medium · HighA record is missing or set in a way this check flags. The level is the same one the full snapshot uses.
- 03ObservedA record was recorded, but the check produced neither a pass nor a finding.
- 04Nothing observedThe check ran but found no record to show.
- 05Not applicableThe check does not apply, for example SPF or DMARC when the host has no MX records.
- 06Not measuredThe DNS lookup failed, so the check is not counted as passed.
What this checker does not do.
- 01It reads records on the exact hostname you enter. For www.example.com it queries www.example.com and _dmarc.www.example.com, not example.com.
- 02The hostname must resolve to an address. A mail-only domain without an A or AAAA record gets no result here.
- 03It does not check DKIM, TLS reporting or DNSSEC, and it does not expand SPF include: terms.
- 04Mail records are read from public DNS only, and no mail is sent. The same run also makes a few ordinary requests to the home page for the other seven checks. It is not a deliverability test, a vulnerability scan or a penetration test.
- 05The result is a point-in-time view; DNS changes can take time to reach every resolver.
Questions about the SPF and DMARC check.
Why does www.example.com show no SPF record?
The checker reads the exact hostname. Mail records usually sit on the domain you send mail from, so enter example.com itself.
Is p=none wrong?
p=none is monitoring mode. It is a normal first step while you read DMARC reports, so it is rated low. Move to quarantine or reject once all legitimate mail passes.
Why is DKIM not checked?
DKIM keys are published under selector names that only the sending services know, so they cannot be found from DNS alone. Check them in the settings of each service that sends your mail.
Does this test whether my mail reaches the inbox?
No. Mail records are read from public DNS only, and no mail is sent; the same run also makes a few ordinary requests to the home page for the other checks. It is not a vulnerability scan or a penetration test. Inbox placement also depends on the sending service, its reputation and each message.