Free DMARC, SPF & DKIM checker

See how a domain’s email authentication looks to Gmail, Outlook and every other receiver, with a belt grade and the exact fixes to make.

What is DMARC?

DMARC is a DNS record that tells mailbox providers what to do with mail that claims to be from your domain but fails authentication: deliver it (p=none), send it to spam (p=quarantine) or refuse it (p=reject). It also asks them to send you daily reports about who is sending as you.

What is SPF?

SPF lists the servers allowed to send mail for your domain. Receivers check the sending server against that list. Each include: of a service like Google or SendGrid costs DNS lookups, and the whole record may use at most 10.

What is DKIM?

DKIM signs each message with a private key; the public key sits in DNS under a selector such as google._domainkey. A valid signature from your own domain proves the message is really yours and wasn’t changed.

What the belts mean

White belt: DMARC at p=none, watching and learning. Orange belt: p=quarantine, spoofed mail goes to spam. Black belt: p=reject, spoofed mail is refused outright. The goal is black belt with every legitimate sender passing.

How the grade works

Every check is scored out of 100. The belt comes from the DMARC policy alone: no belt without a DMARC record, White belt at p=none, Orange belt at p=quarantine and Black belt at p=reject.

DMARC policy up to 40
p=reject34–40 (40 at pct=100)
p=quarantine26–32 (32 at pct=100)
p=none15
No DMARC record0
SPF up to 30
Ends in -all30
Ends in ~all27
No “all” mechanism18
Ends in ?all15
Ends in +all5
Over 10 DNS lookups8 at most
DKIM up to 25
Key found25
Key under 2048 bits−5 each
No key on the selectors checked8
Extras up to 5
MTA-STS3
TLS reporting (TLS-RPT)2

Common problems and how to fix them

No DMARC record

Without DMARC, anyone can send mail that claims to be from your domain and receivers have no instructions for it. Start with p=none and a report address so you can see who sends as you. DMARC Dojo publishes the record and a private report inbox for you.

Stuck at p=none

p=none only monitors: spoofed mail is still delivered. Move to p=quarantine, then p=reject, once your reports show every legitimate sender passing. DMARC Dojo reads the reports and tells you when each step is safe.

SPF over 10 DNS lookups

Each include:, a, mx and redirect costs a DNS lookup, and SPF allows 10. Past that, receivers return a permerror and SPF fails for all your mail. Remove services you no longer use or replace includes with ip4/ip6 ranges. DMARC Dojo hosts your SPF and blocks changes that would go over the limit.

Multiple SPF records

A domain may have only one v=spf1 record. Two or more is an SPF error, so receivers treat SPF as failed. Merge every mechanism into a single record; DMARC Dojo does this automatically when it takes over SPF.

An email service isn’t signing DKIM with your domain

Services like SendGrid, Mailchimp or Amazon SES sign with their own domain by default, which doesn’t count for DMARC. Turn on custom-domain DKIM in each service and publish the CNAMEs or keys it gives you. The Sources view in DMARC Dojo shows exactly which services still need it.

sp=none leaves subdomains open

A strict main policy with sp=none still lets attackers spoof any subdomain, such as billing.yourdomain.com. Remove sp= so subdomains inherit your policy, or set it to quarantine or reject. DMARC Dojo flags this in every domain report.

Checker questions

Why does SPF have a 10-lookup limit?

The SPF standard (RFC 7208) caps the DNS lookups a receiver will make while evaluating your record at 10, to stop SPF being used to flood DNS. Every include:, a, mx, ptr and exists counts, including lookups inside the services you include. Go over and SPF returns a permanent error, which counts as a fail for DMARC.

Why does the checker try common DKIM selectors?

DNS can’t list the DKIM keys a domain has. You have to ask for each selector by name. The checker tries the selectors that Google Workspace, Microsoft 365, SendGrid, Mailchimp, Amazon SES and other common senders use. If yours is different, add it in the selector field.

Is the check safe and private?

Yes. It only reads public DNS records, the same ones every mail server on the internet can see. Nothing is changed and nothing about the domain is stored.

How do I get from p=none to p=reject?

Start at p=none and read the aggregate reports until every service that sends as your domain passes SPF or DKIM with alignment. Then move to p=quarantine at a low pct, raise it to 100, and finish at p=reject. DMARC Dojo reads the reports and tells you when each step is safe.