SPF · DKIM · DMARC · Blacklists

Email Deliverability Checker

Find out why your emails are landing in spam. Enter your domain and get a plain-English report on the DNS records Gmail and Outlook actually check — and the exact record to add for anything that is wrong. Free, instant, no sign-up.

Reads public DNS only Results in seconds Tells you the fix No test email sent
No domain to hand? Try , or .
Public DNS only — no mailbox access, no test message 10 free checks left today

We read the same public records any mail server reads. Your emails, contacts and mailbox are never touched.

How it works

  1. Enter your domain. Just the domain — yourcompany.com. An email address or a full URL works too; we take the domain from it.
  2. We read your public DNS. The same records Gmail, Outlook and Yahoo read when they receive a message from you: MX, SPF, DKIM and DMARC, plus the major blocklists.
  3. You get a grade and a reason. Each check is pass, warning or fail, with what it found and what it means in plain language.
  4. Copy the fix. Anything broken comes with the DNS record to add, ready to paste into your registrar or DNS host.

A real example. A consultancy whose invoices kept landing in clients’ spam folders had a perfectly valid-looking SPF record. The problem was that it had grown to eleven DNS lookups as they added a CRM, an invoicing tool and a help desk — one over the limit of ten. Past that point SPF does not degrade, it fails completely. Nothing in their email settings showed it. Flattening two entries brought it to eight and the invoices started arriving again.

What each check actually means

MX — can your domain receive mail at all?

MX records point at the servers that accept mail for your domain. If they are missing, nothing can reach you. We also use them to work out who runs your email, which is what lets the DKIM check look in the right place.

SPF — which servers are allowed to send as you

A single TXT record listing every service permitted to send email using your domain. Two things go wrong with it. The first is simply not having one. The second is subtler and far more common: SPF permits at most 10 DNS-querying mechanisms across the entire record, including everything each include: pulls in behind the scenes. Every new tool you connect adds to that count, and the day it passes ten your SPF stops working entirely. This checker follows the whole chain and counts it the way a receiving server does.

The ending matters too. -all tells receivers to reject anything not on the list. ~all is a softer "treat as suspicious". +all allows anyone to send as you and should never be there.

DKIM — the signature that proves it was really you

Your mail server signs each message with a private key; the matching public key sits in your DNS. Receivers check the signature to confirm the message came from you and was not modified along the way. Unlike SPF, DKIM survives forwarding, which is why mail sent through a mailing list can still pass.

DKIM records live at selector._domainkey.yourdomain.com, and the selector name is chosen by your provider. There is no way to list them, so a checker has to guess. Most check a handful of generic names and report "not found" for anything else. This one reads your MX records first, identifies the provider, and checks that provider’s selectors as well.

DMARC — what happens when the other two fail

DMARC sets the policy. p=none only collects reports and blocks nothing. p=quarantine sends failures to spam. p=reject refuses them outright. It also carries a rua= address, where receivers send daily reports showing exactly who is sending mail using your domain — including anyone spoofing it.

Most domains that have DMARC at all are sitting on p=none, often for years. That is a reasonable place to start and a poor place to stay: it gives you visibility but no protection.

Blocklists

We check your mail servers against Spamhaus, SpamCop and Barracuda. A listing usually follows a compromised mailbox or an open relay, and it will stop mail arriving no matter how good your records are.

The records, and what good looks like

RecordLives atA healthy example
SPFyourdomain.com (TXT)v=spf1 include:_spf.google.com -all
DKIMselector._domainkey.yourdomain.com (TXT)v=DKIM1; k=rsa; p=MIGfMA0…
DMARC_dmarc.yourdomain.com (TXT)v=DMARC1; p=reject; rua=mailto:[email protected]
MXyourdomain.com (MX)1 aspmx.l.google.com

Changes to DNS are not instant. Most appear within minutes, but allow up to 48 hours before concluding something has not worked, and re-run the check rather than guessing.

Not sure which of these you are missing? Find out in about five seconds.

Check my domain

If your mail is going to spam, work through this in order

  1. Run the check above. Fix anything marked fail before looking at anything else. A missing SPF or DMARC record outweighs every other factor.
  2. Confirm the From domain matches what you authenticated. Sending as [email protected] while only mail.company.com is authorised is a common and invisible mismatch.
  3. Check you only have one SPF record. Two records is not twice as safe; it is invalid, and SPF fails outright. Merge them into one.
  4. Look at your sending history. A domain that has never sent email and suddenly sends a few hundred messages looks exactly like a spammer. Build volume gradually.
  5. Then look at content. Link-heavy messages, attachments, and single-image emails with almost no text all attract filtering — but only once authentication is already correct. Fixing subject lines while SPF is broken wastes everyone’s time.

Common situations

Only some recipients see it in spam

Different providers weigh things differently, and Outlook is typically stricter than Gmail. Partial delivery almost always means authentication is partly working — often SPF passing but DKIM missing.

It worked, then stopped

Something changed. A new email tool pushing SPF over ten lookups, a host migration dropping a DKIM key, or an expired domain record. Re-run the check and compare against what you expect.

Mail from my website form goes to spam

Forms usually send through the web server, not your mail provider, so that server has to be in your SPF too — or better, send through your provider’s SMTP so it is signed properly.

Someone is spoofing my domain

Only DMARC stops that, and only at p=quarantine or p=reject. At p=none you will see it happening in the reports but nothing is blocked.

Limitations, honestly

  • This reads DNS. It cannot see your sending reputation, your complaint rate, or how a specific mailbox provider treats you — all of which matter once authentication is correct.
  • DKIM detection is best-effort. We check your provider’s selectors and the common ones, but a custom selector may not be found. "Not found" means "not found at the usual names", not "does not exist".
  • Blocklist results can be rate limited. When that happens we say the result is unavailable rather than reporting a clean pass we cannot stand behind.
  • A perfect score means your records are right. It does not guarantee the inbox — content and sending history still count.
  • 10 checks a day per visitor, which is plenty for fixing a domain and re-testing.

Email deliverability questions

Most often because one of three DNS records is missing or wrong: SPF, DKIM or DMARC. Mailbox providers use them to decide whether a message really came from your domain. Since February 2024 Gmail and Yahoo expect all three from anyone sending in volume, and mail that fails them is filtered quietly — nothing bounces, so you only find out when somebody says they never received your message. Other causes are a blacklisted sending IP, a brand-new domain with no sending history, or content that looks like a sales blast.

SPF is a public list of the servers allowed to send email using your domain. DKIM is a cryptographic signature added to each message proving it genuinely came from you and was not altered on the way. DMARC ties the two together: it tells receiving servers what to do when a message fails those checks, and it asks them to send you reports about who is sending mail as your domain.

No. It only reads the public DNS records your domain already publishes, which is the same information Gmail and Outlook look at. Nothing is sent, you do not need to give us access to your mailbox, and we never see your messages.

Not necessarily. DKIM records live at a name only your provider knows, called a selector, and there is no way to list them all. This tool works out your mail provider from your MX records and checks that provider's selectors as well as the common ones, which catches most setups. If it still finds nothing, check your provider's DNS instructions for the selector name before assuming DKIM is missing.

SPF allows a maximum of 10 DNS-querying mechanisms across your whole record, including everything pulled in by each include: entry. Go over that and the record is invalid, so SPF fails completely even though the record still looks fine at a glance. It happens gradually: every new mail tool adds another include. This checker follows the whole chain and counts them properly, which is why it sometimes reports a problem other tools miss.

Start at p=none with a rua= address so you receive the reports and can see who is sending as your domain. Once the legitimate senders all pass, move to p=quarantine, then p=reject. Jumping straight to reject before you have read the reports is the usual way to accidentally block your own invoices or newsletters.

-all is stricter: it tells receivers to reject anything from a server not on your list. ~all is a softfail, which usually means "accept but treat as suspicious". -all is the stronger setting, but only move to it once you are certain every service that sends on your behalf is listed, including your CRM, invoicing tool and help desk.

Any time you add a tool that sends email for you, change host or email provider, or notice replies drying up. These records break silently: nothing warns you when a change pushes your SPF over the lookup limit or an auto-renewal drops your DKIM key.

Stop guessing why your email goes to spam

One domain, five seconds, and the exact DNS record to fix whatever is broken.

Check my domain