Email DNS check

Read the public DNS records used in email setup. Enter a DKIM selector to include that key record. This tool checks published DNS data, not a message's authentication result or inbox placement.

Queries go directly from your browser to the selected public DNS resolver. Use public DNS names only. Read how queries are handled.

A public-looking split-DNS name may still be confidential. Do not paste internal-only names.

Query

Enter one selector or its full selector._domainkey.signing-domain name.

Results

Enter a query and press Check email DNS.

MX and SPF answer different questions

MX identifies where incoming mail should be directed. SPF describes authorization for a sending identity and depends on the sending IP and evaluation path. Finding one SPF record is not an SPF pass for a message. Multiple independent SPF records need review; several quoted strings inside one record are a different case. This tool does not expand includes, flatten SPF or calculate the protocol's DNS-lookup limit.

DMARC is more than a visible policy tag

The tool reads _dmarc at the exact domain entered and displays the record's tags. It does not perform complete policy discovery, inheritance, reporting authorization or identifier-alignment checks. No record at a subdomain's exact name does not prove that no inherited policy applies. A monitoring policy is not automatically invalid. Current interpretation follows RFC 9989; legacy tags are preserved rather than silently treated as current guarantees.

DKIM needs a selector

The selector identifies the key record to query. It is commonly shown as s= in a message's DKIM-Signature header, alongside the signing domain in d=. Use the selector and signing domain actually relevant to your service. With no selector, this tool reports Not checked rather than declaring DKIM missing. A retrieved key is not proof that the message's signature is correct.

What is not tested

The tool does not connect to an SMTP server, inspect a mailbox, query blacklists, authenticate a sender or test delivery. A Null MX record intentionally declares that a domain accepts no incoming mail; it should not be replaced just to obtain a green status. Review the intended use of the domain before changing records.

Sources