DMARC & SPF Checker
Short answer
Check a domain's DMARC, SPF, DKIM and MX records, and create SPF and DMARC records.
It is the s= value in the DKIM-Signature header of an email this domain sent. Separate several with commas. Leave it empty to try 24 common selectors.
Large mailbox providers require bulk senders to publish SPF, DKIM and a DMARC record (p=none at least), with the From domain aligned with SPF or DKIM.
DNS records are read from your browser through a public DNS-over-HTTPS resolver. Nothing is sent to RankProof.
What It Does
Looks up a domain's email authentication records and checks them: the MX records (including a null MX), the SPF record with every include followed and the 10-lookup limit counted, the DMARC record against the current standard (RFC 9989), and DKIM keys at the selector you enter or at a set of common selectors. Two more tabs build SPF and DMARC records from a short form.
Why It Matters
SPF, DKIM and DMARC let receiving servers check that email using your domain really comes from you. Large mailbox providers require them from bulk senders, and without an enforced DMARC policy anyone can send email that appears to come from your domain. Small mistakes break them without any warning: a second SPF record, more than 10 DNS lookups or a typo in the DMARC record mean the check fails or the record is ignored.
How It Works
-
Enter a domain, and a DKIM selector if you know it
-
Your browser reads the MX, SPF, DMARC and DKIM records through a public DNS-over-HTTPS resolver
-
Each record is checked: SPF lookups and the all mechanism, the DMARC policy, report addresses and tags, the DKIM key size
-
Read the result for each record, or build a new SPF or DMARC record in the other tabs
Sample input + output
domain: example.com
Mail servers (MX) Null MX: this domain accepts no email
SPF v=spf1 -all
DNS lookups 0 / 10 · other senders: fail (-all)
DMARC v=DMARC1;p=reject;sp=reject;adkim=s;aspf=s
Policy: reject · no rua= address, so no reports
DKIM every selector returns the same empty key (a wildcard) Who Uses This
-
IT administrator
Confirm that SPF stays under the 10-lookup limit after adding a new email service.
-
Marketing manager
Check that the newsletter domain has SPF, DKIM and DMARC before a large send.
-
Agency consultant
Show a client that their DMARC policy is still p=none and build the record for the next step.
Frequently Asked Questions
What is DMARC?
A DNS record that tells receiving servers what to do with email that shows your domain in the From address but fails SPF and DKIM alignment (deliver it, quarantine it or reject it), and where to send reports about that email.
Why is my SPF record over the 10-lookup limit?
Every include, a, mx, ptr and exists mechanism, and the redirect modifier, costs one DNS lookup, and included records can contain more includes. Above 10 the SPF check fails with a permanent error. Remove services you no longer use, or replace an include with the IP ranges the service publishes.
Why can't it find my DKIM key?
DNS offers no way to list DKIM selectors. Without a selector the tool tries a set of common ones. Enter the s= value from the DKIM-Signature header of an email you sent to check the right key.
Is pct= still valid?
DMARC was updated in May 2026 as RFC 9989. The pct, rf and ri tags are no longer part of it, and the new t=y tag marks a policy as a test. Receivers that follow the new standard ignore pct.
Does it send email or change my DNS?
No. It only reads public DNS records. To use a record you built, add it as a TXT record at your DNS provider.
Where do the DNS answers come from?
Your browser asks a public DNS-over-HTTPS resolver directly. The domain is not sent to RankProof, and nothing is stored.