SPF & DMARC Checker
SPF lists the servers allowed to send mail for a domain; DMARC tells receivers what to do with mail that fails. This lookup checks the host first and then its registrable domain, exactly as receiving mail servers do.
Results open in the site's full report, which you can share, compare and re-run.
What it checks
- SPF record (v=spf1) and the domain it was found on
- DMARC record with RFC 7489 organizational-domain fallback
- DMARC policy (none, quarantine or reject), including sp= for subdomains
- Whether the domain receives mail (MX records)
Frequently asked questions
- Why check the parent domain?
- Mail authentication records usually live on the registrable domain (example.com), not on www.example.com. Receivers fall back to the organizational domain for DMARC, so we do too.
- Is p=none enough?
- p=none only monitors. Move to quarantine and then reject once your reports show that legitimate senders pass.
- My site doesn't send email. Do I need SPF?
- Publishing "v=spf1 -all" and a reject DMARC policy stops others from spoofing a domain that never sends mail.
More free tools
- SSL Certificate Checker
- Security Headers Checker
- Technology & CMS Detector
- AI Crawler Access Checker
- llms.txt Checker
- llms.txt Generator
- robots.txt Tester
- XML Sitemap Checker
- Website Speed Test
- Website Carbon Calculator
- Canonical Tag Checker
- Hreflang Checker
- Redirect & Broken Link Checker
- Duplicate Title & Description Checker
- Structured Data Checker
- Core Web Vitals Checker