DomainCanary Start free

Email health check

Check your SPF, DKIM and DMARC records, your MX records and the SpamCop blacklist in one go.

What the email health check covers

The email health check looks up the records that receivers (the mail servers at Gmail, Outlook and the rest) check when your mail arrives. It starts with SPF, DKIM and DMARC. Receivers check those three to spot forged mail that claims to come from you. Then it looks up your MX records, runs a blacklist check on your mail servers and reads the records for encrypted delivery and brand logos.

Check Where we look What a problem means
DMARC _dmarc.example.com Anyone can send mail that claims to come from you
SPF example.com Receivers can't tell which servers may send as you
DKIM selector._domainkey.example.com Your mail has no signature receivers can check
MX example.com Mail sent to your domain has nowhere to go
Blacklist Your mail servers' IPv4 addresses on SpamCop Receivers that use SpamCop refuse mail from that address
MTA-STS _mta-sts.example.com Senders can deliver to you without encryption
TLS-RPT _smtp._tls.example.com Nobody tells you when encrypted delivery to you fails
BIMI default._bimi.example.com Inboxes that show brand logos show none for you

Your results open with every problem we found, worst first. When the fix is a DNS record, we write the record for you to copy. Fix DMARC first, then SPF, then DKIM. Your DMARC policy is where you say what receivers should do with mail that fails the other two.

Each domain's results have their own address, such as /tools/checkup/example.com. Send it to whoever manages your DNS.

Questions

Is my domain on a blacklist?

This check looks up your mail servers' IPv4 addresses on SpamCop, and a clean result covers SpamCop only. We don't check Spamhaus, because its free lists refuse lookups from hosting networks like ours. If an address is listed, find out what sent the spam from it before you ask SpamCop to remove it.

What is an MX record?

It's where you list the servers that take mail for your domain. Without one, sending servers try your domain's own address, and that mail usually bounces. If your domain never takes mail, publish a null MX, 0 ., to say so.

Do I need MTA-STS?

You can receive mail without it. Publish it if you want senders to deliver to you only over an encrypted connection. It needs a TXT record and a policy file on a web server, and our hosted MTA-STS serves that file for you.

What does TLS-RPT do?

It gives senders an address for reports about encrypted deliveries to you that failed. Publish it with MTA-STS, or on its own to learn whether encryption works before you require it.

Why does BIMI need DMARC at quarantine or reject?

Mail providers show your logo only once your DMARC policy is at quarantine or reject. Before that, forged mail could carry your logo too. Gmail also requires a mark certificate (a VMC or a CMC). Our DMARC setup guide covers the steps to get to reject.

How is this different from the SPF, DKIM and DMARC checker?

Use the SPF, DKIM and DMARC checker for more detail on those three records. This check reads the same three, then your mail servers, the blacklist and the delivery records, and puts every problem in one list.

A DNS lookup only proves what you published. Aggregate DMARC reports show which of your real senders pass, and they're the next thing to read once these records are right.

One lookup now, or every report read for you

This page reads the records receivers will check on the next message. Receivers also send reports, naming each host that sent as your domain and whether its mail passed. We read every one and mail you a summary each Monday. Your first domain is free.

Start watching your domain

Free for your first domain · No card · Per-source totals kept for life

The other tools