Email DNS check
Read the public DNS records used in email setup. Enter a DKIM selector to include that key record. This tool checks published DNS data, not a message's authentication result or inbox placement.
Queries go directly from your browser to the selected public DNS resolver. Use public DNS names only. Read how queries are handled.
A public-looking split-DNS name may still be confidential. Do not paste internal-only names.
Results
Enter a query and press Check email DNS.
This link includes the queried name, not saved results. Review exported DNS answers before sharing; they may contain public tokens or other sensitive-looking data.
MX and SPF answer different questions
MX identifies where incoming mail should be directed. SPF describes authorization for a sending identity and depends on the sending IP and evaluation path. Finding one SPF record is not an SPF pass for a message. Multiple independent SPF records need review; several quoted strings inside one record are a different case. This tool does not expand includes, flatten SPF or calculate the protocol's DNS-lookup limit.
DMARC is more than a visible policy tag
The tool reads _dmarc at the exact domain entered and displays the record's tags. It does not perform complete policy discovery, inheritance, reporting authorization or identifier-alignment checks. No record at a subdomain's exact name does not prove that no inherited policy applies. A monitoring policy is not automatically invalid. Current interpretation follows RFC 9989; legacy tags are preserved rather than silently treated as current guarantees.
DKIM needs a selector
The selector identifies the key record to query. It is commonly shown as s= in a message's DKIM-Signature header, alongside the signing domain in d=. Use the selector and signing domain actually relevant to your service. With no selector, this tool reports Not checked rather than declaring DKIM missing. A retrieved key is not proof that the message's signature is correct.
What is not tested
The tool does not connect to an SMTP server, inspect a mailbox, query blacklists, authenticate a sender or test delivery. A Null MX record intentionally declares that a domain accepts no incoming mail; it should not be replaced just to obtain a green status. Review the intended use of the domain before changing records.