FREE TOOL / NO ACCOUNT / RUNS ON THE PAGE YOU GIVE IT

SPF, DKIM and DMARC checker

The four DNS records that decide whether your mail arrives and whether anyone else can send as you, checked and scored, with your SPF record's real lookup cost counted.

We read your MX, SPF, DMARC and DKIM records over DNS, follow every include in your SPF record to count its real lookup cost, and probe the DKIM selectors big senders use.

QUESTIONS ABOUT THIS TOOL

Why does an SPF record have a ten lookup limit?
Every include, a, mx, ptr and exists mechanism costs the receiver a DNS query, and the limit exists so one message cannot trigger dozens. Go over it and the result is a permanent error, which means SPF fails for every message you send, not just some. This tool follows your includes and counts the real total, because the record you can see is rarely the whole cost.
What is the difference between ~all and -all?
Both say the listed servers are the only authorised senders. ~all is a soft fail: mail from anywhere else is accepted and marked. -all is a hard fail: it is rejected. Start on ~all while you are still finding services that send on your behalf, then move to -all once the reports are clean.
My DMARC policy is p=none. Is that doing anything?
It is collecting reports and blocking nothing. That is the correct place to start, because it shows you every service sending as you before you turn enforcement on. It is the wrong place to stay, because a monitor-only policy stops no forgery at all.
Why can you not tell me for certain whether DKIM is set up?
A DKIM key lives at a selector, and a selector can be any name the sender chooses. DNS has no way to list what exists under a name, so nobody can enumerate them. We probe the selectors the large providers use, so finding one is proof it is there and finding none is not proof it is missing. The certain answer is in a message header from a real send.
Does any of this affect my search rankings?
Not directly. It affects whether your mail arrives, which matters for outreach, link building and every transactional message a site sends. A domain that fails authentication also gets forged more, and a forgery wave is a reputation problem that does reach search.
Do I need all four?
You need MX to receive and SPF plus DMARC to stop forgery. DKIM matters most if your mail gets forwarded, because forwarding breaks SPF and DKIM survives it. In practice DMARC only enforces properly once at least one of SPF or DKIM aligns with your domain.

A TOOL CHECKS ONCE. SEOBUILDER KEEPS WATCH.

We can watch this for you.

These records rot. A new sending tool gets added to SPF and pushes it over the lookup limit, a DMARC policy sits on none for two years, a key is rotated and the old selector stays. We check yours on a schedule and tell you when something changes, alongside whether AI answers name you for your category.

START FREE, NO CARD