# DMARC & SPF Checker

https://rankproof.eu/tools/monitoring-dmarc-checker

## Short answer

Check a domain's DMARC, SPF, DKIM and MX records, and create SPF and DMARC records.

## What It Does

Looks up a domain's email authentication records and checks them: the MX records (including a null MX), the SPF record with every include followed and the 10-lookup limit counted, the DMARC record against the current standard (RFC 9989), and DKIM keys at the selector you enter or at a set of common selectors. Two more tabs build SPF and DMARC records from a short form.

## How It Works

1. Enter a domain, and a DKIM selector if you know it
2. Your browser reads the MX, SPF, DMARC and DKIM records through a public DNS-over-HTTPS resolver
3. Each record is checked: SPF lookups and the all mechanism, the DMARC policy, report addresses and tags, the DKIM key size
4. Read the result for each record, or build a new SPF or DMARC record in the other tabs

## Sample input + output

INPUT

```text
domain: example.com
```

OUTPUT

```text
Mail servers (MX)   Null MX: this domain accepts no email
SPF                 v=spf1 -all
                    DNS lookups 0 / 10 · other senders: fail (-all)
DMARC               v=DMARC1;p=reject;sp=reject;adkim=s;aspf=s
                    Policy: reject · no rua= address, so no reports
DKIM                every selector returns the same empty key (a wildcard)
```

## Why It Matters

SPF, DKIM and DMARC let receiving servers check that email using your domain really comes from you. Large mailbox providers require them from bulk senders, and without an enforced DMARC policy anyone can send email that appears to come from your domain. Small mistakes break them without any warning: a second SPF record, more than 10 DNS lookups or a typo in the DMARC record mean the check fails or the record is ignored.

## Who Uses This

- **IT administrator**: Confirm that SPF stays under the 10-lookup limit after adding a new email service.
- **Marketing manager**: Check that the newsletter domain has SPF, DKIM and DMARC before a large send.
- **Agency consultant**: Show a client that their DMARC policy is still p=none and build the record for the next step.

## Frequently Asked Questions

### What is DMARC?

A DNS record that tells receiving servers what to do with email that shows your domain in the From address but fails SPF and DKIM alignment (deliver it, quarantine it or reject it), and where to send reports about that email.

### Why is my SPF record over the 10-lookup limit?

Every include, a, mx, ptr and exists mechanism, and the redirect modifier, costs one DNS lookup, and included records can contain more includes. Above 10 the SPF check fails with a permanent error. Remove services you no longer use, or replace an include with the IP ranges the service publishes.

### Why can't it find my DKIM key?

DNS offers no way to list DKIM selectors. Without a selector the tool tries a set of common ones. Enter the s= value from the DKIM-Signature header of an email you sent to check the right key.

### Is pct= still valid?

DMARC was updated in May 2026 as RFC 9989. The pct, rf and ri tags are no longer part of it, and the new t=y tag marks a policy as a test. Receivers that follow the new standard ignore pct.

### Does it send email or change my DNS?

No. It only reads public DNS records. To use a record you built, add it as a TXT record at your DNS provider.

### Where do the DNS answers come from?

Your browser asks a public DNS-over-HTTPS resolver directly. The domain is not sent to RankProof, and nothing is stored.

## Related Tools in Monitoring

- [Uptime Check](https://rankproof.eu/tools/monitoring-uptime-check)
- [Technology Stack Detector](https://rankproof.eu/tools/monitoring-technology-stack)
