Free Email Security Checker

Check SPF, DKIM, and DMARC records for any domain

Enter any domain to look up its email authentication DNS records. This tool checks for SPF, DKIM, and DMARC configurations that protect your domain against email spoofing, phishing, and deliverability issues — and tells you exactly what's missing or misconfigured.

Trusted by teams at

Ramp
Pilot
Vercel
Stripe
Better Auth
SST
OpenCode

How it works

How Email Security Checker works

01

Enter a domain

Type any domain name (e.g., example.com). No need to add a protocol — just the bare domain.

02

DNS record lookup

We query DNS-over-HTTPS to look up TXT records for SPF, the _dmarc subdomain for DMARC policy, and common DKIM selectors to check for email authentication records.

03

Get a security assessment

Each record is analyzed for completeness, strength, and common misconfigurations. You get specific recommendations to improve your email security posture.

Features

What Email Security Checker checks

SPF record validation

Checks for the presence and correctness of your SPF record, which tells receiving mail servers which IP addresses are authorized to send email on behalf of your domain.

DMARC policy analysis

Looks up your _dmarc TXT record and analyzes the policy (none, quarantine, reject), reporting configuration, and alignment settings that determine how spoofed emails are handled.

DKIM selector check

Queries common DKIM selectors to verify that your domain has DomainKeys Identified Mail configured, which cryptographically signs outgoing emails to prevent tampering.

Actionable fix recommendations

For every missing or misconfigured record, you get the exact DNS TXT record value to add, with explanations of what each directive does and why it matters.

Use cases

Who should use the free Email Security Checker

IT Administrators

Verify your domain's email authentication is correctly configured after setting up a new mail provider, changing DNS hosting, or adding third-party email services.

Security Teams

Audit email security posture across your organization's domains to prevent spoofing attacks. Identify domains without DMARC enforcement that could be used in phishing campaigns.

Marketing Teams

Diagnose email deliverability issues caused by missing or misconfigured SPF, DKIM, or DMARC records that cause legitimate emails to land in spam folders.

FAQ

Frequently asked questions

Everything you need to know about the free Email Security Checker.

Go beyond Email Security Checker

This free Email Security Checker checks a handful of things. Maced's AI pentest checks thousands.

Get a full autonomous penetration test — including OWASP Top 10, authentication flaws, business logic errors, API security, and more — with a compliance-ready report in hours.

Proof of exploit on every finding · SOC 2 & ISO 27001 compatible