Skip to main content

Nothing in a small business is more quietly expensive than email that never arrives. Quotes go unanswered, invoices go unpaid, and your newsletter vanishes. Because almost nothing bounces, you assume people are ignoring you. Usually they never received it.

The cause is nearly always authentication. Gmail, Yahoo and Microsoft now require SPF, DKIM and DMARC to be set up and correctly aligned, and since November 2025 Gmail has moved from quietly filtering non-compliant mail to rejecting it outright with a permanent error. This tool reads those records from public DNS and tells you, in plain English, what is missing and how to fix it.

Check my domain
What it checks
  • SPF record and its lookup count
  • DKIM signing keys on common selectors
  • DMARC policy and reporting address
  • MX records and mail routing
  • Whether your policy is enforcing or only monitoring

What do SPF, DKIM and DMARC actually do?

Think of them as a guest list, a signature and a rule. SPF is a DNS record listing which servers are allowed to send email using your domain. DKIM adds a cryptographic signature to every message so the receiving server can prove it was really you and that nothing was altered in transit. DMARC ties the two together: it tells receiving servers what to do when a message fails, and it is the only one of the three that sends you reports about who is using your domain.

Why do my emails go to spam when all three are set up?

Because passing is not the same as aligning. The domain your recipient sees in the From line has to match the domain used by SPF or DKIM. Plenty of businesses pass each check individually and still fail DMARC, because their invoicing software, CRM or marketing platform sends from a different domain underneath. If your records look right but mail still disappears, alignment is almost always the culprit, and it is the one thing that cannot be confirmed from DNS alone.

Is "p=none" good enough?

No, and most domains that have DMARC are stuck there. p=none is monitoring only: it reports what is happening but instructs receivers to deliver spoofed mail anyway. It is the correct place to start and the wrong place to stay. Moving to p=quarantine and then p=reject is what actually stops someone sending fake invoices in your name, and it is increasingly what large senders and insurers expect to see.

How many DNS lookups is too many?

SPF has a hard limit of ten DNS lookups. Go over it and the check does not just warn, it fails outright, exactly as if you had no SPF at all. Every include: in your record counts, and each one can pull in more. Businesses that have added a mail provider, a CRM, an invoicing tool and a marketing platform over the years routinely blow through the limit without any warning that they have done so.

How do I read the result?

Anything marked as needing fixing is costing you delivered mail today. Warnings are working but weak, and are usually a fifteen-minute change. One honest caveat: DKIM selector names cannot be enumerated from outside, so we probe the ones the major providers use. If yours is custom we may show a warning even though signing is on. Every other check in this tool is measured directly and is definitive.

What good looks like

The thresholds Gmail, Yahoo and Microsoft actually apply to bulk senders.

Signal Bare minimum What we recommend
SPF Record exists, ends ~all Ends -all, under 10 DNS lookups
DKIM Enabled, 1024-bit key Enabled, 2048-bit key, rotated
DMARC Published at p=none p=quarantine or p=reject, with rua reporting
Alignment SPF or DKIM aligned Both aligned with the visible From domain
Spam complaints Under 0.3% Under 0.1%
Unsubscribe A working link One-click list unsubscribe header

How to fix email that lands in spam

  1. 1
    Run the check above

    Get the current state of SPF, DKIM and DMARC on your domain before changing anything.

  2. 2
    List every service that sends as you

    Mail provider, website forms, invoicing, CRM, marketing platform, booking system. Missing one is the usual reason a fix does not stick.

  3. 3
    Publish or repair SPF

    One record only, listing every legitimate sender, ending in ~all or -all, and staying under ten DNS lookups.

  4. 4
    Turn on DKIM signing

    Enable it in your mail provider and publish the key it gives you at the selector it specifies.

  5. 5
    Publish DMARC at p=none with reporting

    Add a rua address so you can see who is sending as you before you enforce anything.

  6. 6
    Read the reports, then enforce

    Once only your legitimate senders appear, move to p=quarantine and then p=reject.

Fair questions.

Is this really free?

Yes, with no signup and no meaningful limit. It reads public DNS records, which costs us almost nothing. We sell the paid fix to people who would rather not touch DNS themselves, but the check is genuinely free either way and we show you the full result.

Do I need to change email providers to fix this?

Almost never. This is DNS and configuration work on a domain you already own, and it works with Google Workspace, Microsoft 365 and most providers exactly as they are. Nothing about how your team sends email changes.

Why does it say DKIM is missing when I know it is on?

DKIM keys live at a selector name that cannot be listed from outside, so we test the ones used by the major providers. If you use a custom selector we will not find it. Everything else in the result is measured directly.

How long do DNS changes take to work?

Usually within an hour and almost always within 48. Reputation recovery takes longer: if your domain has been failing for months, expect a few weeks of consistent sending before inbox placement fully recovers.

Will this tell me if I am blocklisted?

Not directly. This covers authentication, which is the underlying cause in most cases. Blocklisting is usually the symptom that follows. Our paid service includes blocklist checks and delisting.

What is a DMARC rua address?

It is the mailbox that receives aggregate reports about mail sent using your domain. Without it DMARC is close to pointless, because you have no way of seeing whether your legitimate mail is passing or who is spoofing you.

Does this matter if I only send a few emails a day?

Yes. The bulk-sender rules are strictest above 5,000 messages a day, but authentication affects everyone. A single unanswered quote is worth more than the fifteen minutes this takes to fix.

Can I check a domain I do not own?

Yes. Every record this tool reads is public DNS, the same information any receiving mail server looks up. It is a common way to check a supplier or a competitor.

Run the check.

Takes about ten seconds. No email address, no report held back.

Check my domain
Would rather not do it yourself?
Email Deliverability & Domain Health

Stop landing in spam. SPF, DKIM and DMARC set up properly so your email actually reaches Gmail, Outlook and Yahoo.

$990
See the service
Joshua from Logan City just received three quotes for Mobile App development. Get your 3 quotes now
7 minutes ago