SPF, DKIM and DMARC checker
Read all three of your domain's email authentication records in one go.
How SPF, DKIM and DMARC work together
Publishing SPF, DKIM and DMARC creates the core email authentication records for your domain. SPF lists the hosts allowed to put your domain in the envelope sender. DKIM signs headers and body content, while DMARC tells receivers what to do when those checks fail.
| Record | DNS location | What it settles | Failing on its own |
|---|---|---|---|
| SPF | example.com |
Matches connecting IP against envelope sender | DMARC still passes if DKIM aligns, but receivers may reject early |
| DKIM | selector._domainkey |
Proves signed headers and body stayed intact | DMARC still passes if SPF aligns, but forwarded mail can break |
| DMARC | _dmarc.example.com |
Sets receiver policy and requests aggregate reports | Receivers use standard spam filtering and send no reports |
Questions
Do I need all three?
Yes. Forwarders break SPF by relaying mail without rewriting the envelope sender. Mailing lists break DKIM by altering subjects. Google's sender guidelines require SPF and DKIM together for domains sending 5,000 or more messages a day to Gmail, plus DMARC at p=none or stricter.
Does p=none stop spoofing?
No. A p=none DMARC policy tells receivers to deliver failing mail normally
while sending you aggregate reports. Use it to find all your legitimate senders. Follow
our DMARC setup guide and test with our
DMARC checker before moving to quarantine or reject.
Can I publish two SPF records?
No. RFC 7208 forbids publishing two v=spf1 records on one name. Receivers
finding two return a permerror and evaluate neither. Test your domain with our
SPF checker to spot duplicates and fix syntax
errors.
Why does email from my platform fail DMARC?
Your platform might bounce to its own domain and sign with its own d= value.
Both checks pass under its name, not yours. This breaks
identifier alignment, so every message fails DMARC.
At p=reject, receivers block that mail alongside actual spam.
How do I find my DKIM selector?
Leaving the selector field blank in our lookup tool makes it try common names. If that fails, log into your sending platform's DNS settings to find the live DKIM selector. You can then test it directly with our DKIM checker.
Why did my SPF record hit the lookup limit?
RFC 7208 allows 10 DNS lookups for a whole SPF evaluation, counting every mechanism nested inside every include. Past 10 DNS lookups a receiver returns permerror, which stops SPF from giving DMARC an aligned pass. Follow our SPF 10-lookup limit guide to flatten your record.
A DNS lookup only proves what you published. Aggregate reports show which of your actual senders pass in production. Sign up for DomainCanary to parse your reports and spot broken senders.
Stop reading raw DMARC XML reports by hand
Mailbox providers generate XML files containing IP addresses, volumes, and authentication pass rates for your domain. DomainCanary digests that data into one concise weekly summary, highlighting what changed and what needs attention. Your first domain is free, with per-source totals kept for the life of the account.
Monitor your domain freeFree for your first domain · No card · Per-source totals kept for life