How often should I check my email security?
Check monthly, or whenever you change email providers, marketing platforms, or DNS records. Configuration drift is common when teams add new senders.
Free DNS mail security check
Get a live SPF, DMARC, DKIM, MTA-STS, and TLS-RPT posture report with MX, TXT, DNS servers, registrar data, MTA-STS policy mode, policy-host SSL, and exportable client-ready summaries.
Results are generated from live DNS lookups. No account required.
See soft-fail policies, lookup pressure, and whether authorized senders are declared correctly.
Review policy strength, RUA/RUF coverage, and external reporting authorization in one place.
Confirm signing posture, MX routing, TXT records, nameservers, and registration expiration.
Check monthly, or whenever you change email providers, marketing platforms, or DNS records. Configuration drift is common when teams add new senders.
p=none monitors authentication failures without blocking them. It is useful for visibility, but it does not stop spoofed mail. Move toward quarantine or reject once legitimate sources are aligned.
SPF allows a maximum of 10 DNS lookups. Too many include/a/mx mechanisms can cause SPF to fail and hurt delivery. Flattening or consolidating includes often fixes this.
MTA-STS mode none is effectively off. Testing (reporting) asks supporting senders to follow the policy and report TLS failures without blocking delivery. Enforce tells those senders to refuse delivery when they cannot complete valid TLS to your published MX hosts.
Yes. Use Send to email, Copy, Export PNG, or Export PDF to share a clean DNS posture summary. For ongoing monitoring across many domains, start a managed workspace.