Check Your Domain's Email Security in One Report
One all-in-one report covering DMARC records to prevent spoofing, SPF records to authorise your sending servers, and MTA-STS, DANE and TLS reporting for encrypted transport. Get email security feedback instantly with actionable recommendations from the best free analyzer.
Only need one check? Use the standalone DMARC checker, SPF record checker or TLS checker.
What this check covers
One domain, three result cards. Each card leads with its overall status, then gives the record as published, what receiving mail servers make of it, and the fixes to apply in order of importance.
- DMARC. Finds the DMARC record for the domain or, following RFC 9989, the one it inherits from its organisational domain, and reports the domain, subdomain and non-existent subdomain policies, testing mode, deprecated tags and whether reports are being collected. Read more on the DMARC checker page.
- SPF. Validates the SPF record syntax and counts DNS lookups against the RFC 7208 limit of 10, including every nested include, so you know whether your record still authenticates anything. Read more on the SPF record checker page.
- TLS. Checks the TLS-RPT reporting record, the MTA-STS record and policy file, DNSSEC and DANE TLSA records, then reports the effective transport security level for inbound email. Read more on the TLS checker page.
The SPF card can take a little longer to appear than the other two, because the checker walks the full include chain the way a receiving server does.