Free SPF & DMARC Checker

Enter a domain to see whether its SPF and DMARC records are set up correctly — with plain-English fixes, instantly, and no signup.

Try:

What this tool checks

SPF and DMARC are the DNS records that stop other people sending email as your domain — and that keep your own mail out of spam. This tool reads both and flags the problems that actually bite:

  • SPF— whether a record exists, whether there's exactly one (more than one is invalid), and how it ends: -all, ~all, ?all or the dangerous +all.
  • DMARC — whether a record exists at _dmarc.yourdomain.com, whether the policy is enforced (quarantine/reject) or only monitoring (none), its coverage (pct), and whether it's collecting aggregate reports (rua).

Why it matters

Weak or missing email authentication is why legitimate mail lands in spam and why scammers can spoof your domain. It's also the prerequisite for a logo next to your emails: BIMI only works once DMARC is enforced at pct=100. Getting SPF and DMARC right is the foundation everything else builds on.

Email authentication is one of several clocks and configurations worth keeping an eye on. The two that take a site offline entirely — domain registration and SSL certificate expiry — are what DomainChest watches for you automatically. Add a domain once and it emails you well before either lapses.

Frequently asked questions

What are SPF and DMARC?

They're two of the DNS records that stop other people from sending email as your domain. SPF lists which servers are allowed to send mail for you. DMARC ties SPF and DKIM together and tells receiving servers what to do when a message fails — and asks them to report back. Together they protect your domain from spoofing and improve deliverability.

What does 'DMARC enforced' vs 'monitoring only' mean?

A DMARC policy of p=none is monitoring only: receivers report failures but still deliver the mail. p=quarantine sends failing mail to spam, and p=reject blocks it outright — those two are 'enforced'. The safe path is to start at p=none with a reporting address, confirm your legitimate mail passes, then move to quarantine and finally reject.

Why does my SPF record matter for the '-all' at the end?

The final mechanism tells receivers how to treat servers not on your list. -all means 'fail anything else' (strict, recommended), ~all means 'soft fail' (mark suspicious), ?all is neutral, and +all authorizes everyone — which defeats the point. If there's no 'all' at all, receivers are left guessing.

Does this check DKIM too?

Not directly. DKIM records live at a selector you choose (like selector1._domainkey.yourdomain.com), and there's no way to discover the selector from DNS alone, so a generic checker can't reliably fetch it. DMARC is what ties SPF and DKIM results together, which is why this tool focuses on SPF and DMARC.

Is it free?

Yes, completely free and no account needed. If you'd also like to be emailed before your domain or SSL certificate expires, you can track those with a free DomainChest account (up to three domains).


Related tools: WHOIS & DNS Lookup for the full DNS picture, Domain & SSL Expiry Checker, and SSL Certificate Checker.

One less thing to remember to check

Store your domains in a chest, so you never forget one again.

Start free — 3 domains