Free DNS mail security check

Check your domain's email authentication and SMTP TLS

Get a live SPF, DMARC, DKIM, MTA-STS, and TLS-RPT posture report with MX, TXT, DNS servers, registrar data, MTA-STS policy mode, policy-host SSL, and exportable client-ready summaries.

Results are generated from live DNS lookups. No account required.

See soft-fail policies, lookup pressure, and whether authorized senders are declared correctly.

Review policy strength, RUA/RUF coverage, and external reporting authorization in one place.

Confirm signing posture, MX routing, TXT records, nameservers, and registration expiration.

Frequently asked questions

How often should I check my email security?

Check monthly, or whenever you change email providers, marketing platforms, or DNS records. Configuration drift is common when teams add new senders.

What does a DMARC policy of p=none mean?

p=none monitors authentication failures without blocking them. It is useful for visibility, but it does not stop spoofed mail. Move toward quarantine or reject once legitimate sources are aligned.

Why does SPF lookup count matter?

SPF allows a maximum of 10 DNS lookups. Too many include/a/mx mechanisms can cause SPF to fail and hurt delivery. Flattening or consolidating includes often fixes this.

What do MTA-STS modes mean?

MTA-STS mode none is effectively off. Testing (reporting) asks supporting senders to follow the policy and report TLS failures without blocking delivery. Enforce tells those senders to refuse delivery when they cannot complete valid TLS to your published MX hosts.

Can I share these results with a client?

Yes. Use Send to email, Copy, Export PNG, or Export PDF to share a clean DNS posture summary. For ongoing monitoring across many domains, start a managed workspace.