SPF, DKIM & DMARC Checker

Enter your domain to look up the three DNS records that decide whether criminals can send email as your business. You will see each record exactly as it is published, what is wrong with it, and what to change. Lookups run from your browser using public DNS, so nothing is sent to us.


Enter the domain you send email from. No “www” and no “@”.

Optional. Leave blank and we will try the common ones.


Use — Guide

How to use this tool

  1. Enter the domain you send email from, without www or an @ symbol.
  2. Optionally enter your DKIM selector if you know it, so we look in exactly the right place.
  3. Read the record we found for SPF, DKIM and DMARC, shown exactly as it is published.
  4. Work through the fixes listed under any record marked Warn or Fail.

FAQ — Questions

Frequently asked questions

01What is SPF, DKIM and DMARC in plain English?

They are three DNS records that together prove your email is really from you. SPF lists the servers allowed to send as your domain, DKIM signs each message so it cannot be altered in transit, and DMARC tells receiving mail servers what to do when a message fails those checks. Without all three, anyone can send email that appears to come from your business.

02Why does the checker say my DKIM was not found when I know it is set up?

DKIM records are published under a selector, and the selector name differs between mail providers. We probe the selectors your mail provider normally uses plus a list of common ones, but we cannot know a custom selector. If yours is not found, enter your selector in the optional field and run the check again. Your mail platform shows the selector in its DKIM settings.

03Is my domain sent to Peritus Digital when I run a check?

No. The lookups run in your browser against public DNS-over-HTTPS resolvers, so the domain you type never reaches us. Nothing is sent to Peritus Digital unless you choose to contact us.

04What should my DMARC policy be set to?

p=reject is the goal, because it tells inboxes to throw away forged mail outright. Most businesses start at p=none to collect reports, then move to p=quarantine and finally p=reject once the reports show all legitimate mail is passing. Staying at p=none gives you visibility but no protection.

05How long do changes to these records take to work?

DNS changes usually apply within minutes, but can take up to a few hours depending on the TTL on your existing records. Re-run this check after you publish a change to confirm it is live.

Need help closing these gaps?

Getting SPF, DKIM and DMARC right takes care — we do it properly.

Misconfigured or missing email-authentication records are one of the most common ways criminals impersonate a business to defraud its customers and staff. Our Newcastle team reviews your records, publishes the fixes, and moves your DMARC policy safely towards p=reject without breaking legitimate mail.

Prefer to build the records yourself? Use ourSPF & DMARC Record Generator.