Search 100+ free tools… (e.g. json, vpn, password) ⌘K
Link Tools Dereferer Hide Referrer Link URL Shortener Affiliate Cloaker PayPal Links PayPal DonationPayPal Links Privacy Tools Password Generator Cloudflare Resolver My Referrer Torrent Tools Magnet → Torrent Torrent → Magnet Torrent Editor Pirate Bay Proxies Movierulz Proxies ExtraTorrent Proxies Dev Tools Base64 Encoder Hash Generator HTTP Headers Disposable Email Checker Company Blog About Us Contact Anonymize Free
Security Tool

SPF & DMARC Checker

Check the email authentication DNS records for any domain — SPF, DMARC and DKIM. Validate your setup and find misconfigurations that allow email spoofing.

Try: google.com   github.com   amazon.com

Frequently Asked Questions

What are SPF and DMARC and why do I need them?
SPF (Sender Policy Framework) specifies which mail servers are authorised to send email on behalf of your domain. DMARC tells receiving mail servers what to do with emails that fail SPF or DKIM checks. Together they protect your domain from being used in phishing and spoofing attacks.
My SPF record lookup failed — what does that mean?
A failed SPF lookup means either your domain has no SPF record in DNS, the record has a syntax error, or it exceeds the 10 DNS lookup limit imposed by the SPF specification. Missing or invalid SPF records increase the chance of your legitimate emails being marked as spam.
What DMARC policy should I set?
Start with p=none to monitor email authentication without affecting delivery. Once you have confirmed your legitimate mail sources are properly authenticated, move to p=quarantine (send failures to spam) and then p=reject (block failures entirely) for maximum protection.
What is SPF and why do I need it?
SPF (Sender Policy Framework) is a DNS record that lists which mail servers are authorised to send email from your domain. Without SPF, anyone can send email that appears to come from your domain, enabling phishing and spoofing attacks.
What is the difference between DMARC p=none, quarantine and reject?
p=none is monitoring-only mode — emails still deliver normally but reports are sent. p=quarantine sends failing emails to spam. p=reject blocks failing emails entirely and is the recommended setting for fully protected domains. Start with p=none, then escalate.
Why is DKIM not detected?
DKIM records are stored under a selector subdomain (e.g. google._domainkey.yourdomain.com). This tool checks the most common selectors automatically. If your selector is custom, you will need to check it manually. DKIM is configured in your email provider — contact them for your selector name.
My domain has SPF but still gets spoofed — why?
SPF alone is not enough. You also need DMARC to enforce the SPF policy. Without DMARC, even a valid SPF record does not prevent spoofing because email clients are not required to act on SPF failures. DMARC with p=reject gives full protection.
Related: Email Header Analyzer DNS Lookup Security Headers Check SSL Checker
🛡️
Your IP address and DNS queries are visible to your ISP. Protect your privacy with a trusted VPN — tested and recommended by Anonymiz.
See Recommended VPNs →

SPF, DKIM and DMARC in plain terms

Email was designed with no way to prove who sent a message, which is why spoofing and phishing are so easy. Three DNS records fix that for your domain, and this checker looks them up and flags anything missing or misconfigured.

Common mistakes

Why it matters now

Since 2024 Gmail and Yahoo require bulk senders to have SPF, DKIM and a DMARC record, and mail from domains without them is filtered more harshly. If a domain sends no email at all, publish v=spf1 -all and a DMARC policy of p=reject so nobody can send in its name.

Related articles

Related Tools

🔎
DNS Lookup
Query TXT, MX and other records
🗂️
DNS Record Checker
See every DNS record at once
📧
Email Header Analyzer
Trace an email delivery path
🔍
WHOIS Lookup
Look up domain registration info
🚫
IP Blacklist Checker
Check if your IP is blacklisted
🛡️
DNS Leak Test
Check if your VPN leaks DNS
Done!