<15 min Response

Since 2015

Cyber Essentials Certified

Check Your IT Score

Remote SOS Support

Free • Instant • No sign-up

Free DMARC and SPF checker

Could a criminal send an email that looks like it came from your business? Enter your domain to test its SPF, DKIM and DMARC records, and get a plain-English result with what to fix.

We look up your domain’s public DNS records using Google Public DNS, with Cloudflare as a backup. Nothing you enter is sent to us or stored by us.

Plain English

SPF, DKIM and DMARC: what they actually do

Email was never designed to check who a message is really from. These three records, published in your domain’s DNS, fill that gap. You need all three working together.

SPF

Who is allowed to send

A list of the mail servers and services allowed to send email for your domain, such as Microsoft 365, your accounts software or your newsletter tool.

DKIM

Proof it was not tampered with

A digital signature each of your email services adds to the emails it sends, once DKIM is switched on. The receiving server checks it against a public key in your DNS to confirm the email is genuine and unchanged.

DMARC

What to do with fakes

Tells receiving servers what to do when an email claiming to be from you does not pass SPF or DKIM for your domain: let it through, send it to spam or reject it. It can also send you reports.

Email arrivesclaiming to be from you@yourcompany.co.uk
SPF and DKIM checkedWas it sent by an approved server, with a valid signature?
Passes: treated as genuineFails, p=quarantine: spam folderFails, p=reject: usually blocked

Why it matters

A spoofed email from your domain is a gift to fraudsters

If your domain has no DMARC policy, or one set to none, a criminal can send an email that shows your real address in the From line, and many inboxes will accept it. That is how a lot of invoice fraud starts: a convincing email to your customers or suppliers saying your bank details have changed.

Our guide to invoice fraud and business email compromise explains how these scams work, and our free phishing test shows what to look out for.

Getting these records right also helps your genuine email. The big email providers now check them, so invoices, quotes and newsletters sent from badly set up domains are more likely to land in spam.

NCSCThe National Cyber Security Centre says a DMARC policy of reject on all your domains is the best way to prevent spoofing of your email.
Google, since February 2024Senders of around 5,000 or more emails a day to personal Gmail accounts must have SPF, DKIM and DMARC, and every sender needs at least SPF or DKIM. Since November 2025 Gmail rejects some email that does not comply.
Microsoft, since May 2025Domains sending more than 5,000 emails a day to Outlook.com, Hotmail and Live addresses must have SPF, DKIM and DMARC, or Microsoft rejects their email.

How to fix a bad result

Getting to DMARC reject without breaking your email

  1. List everything that sends email as youMicrosoft 365 or Google Workspace, plus your accounts software, CRM, website forms, newsletter tool and anything else that sends from your domain.
  2. Fix SPFKeep one SPF record that includes every one of those services, stays within 10 DNS lookups and ends in -all or ~all.
  3. Turn on DKIM everywhereSwitch on DKIM signing in Microsoft 365 or Google Workspace, and in each other service that sends for you.
  4. Publish DMARC at p=none with reportsAdd a record such as v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.co.uk and read the reports for a few weeks to find anything you missed.
  5. Move to quarantineWhen your genuine email is passing, change to p=quarantine, so failing email goes to spam.
  6. Finish at rejectThen move to p=reject, the policy the NCSC recommends. Keep watching the reports for a few weeks afterwards, and whenever you add a new service that sends email.

Do not jump straight to reject. If a service that sends email for you is missing from SPF or DKIM, its emails will be blocked too. Go step by step and watch the reports.

Free • No obligation • Senior engineer

Want us to fix your email security?

Tell us your domain and a senior engineer will look at your SPF, DKIM and DMARC records with you, find every service that sends email as you, and give you a safe plan to get to DMARC reject without blocking your own email.

What you get

  • Your SPF, DKIM and DMARC records checked
  • Every service that sends as you identified
  • A step-by-step plan to DMARC reject
  • Microsoft 365 email security reviewed

Book your free IT & cyber review

Free, no obligation. We only use your details to arrange the review. Privacy policy.

FAQ

DMARC, SPF and DKIM: common questions

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving mail servers what to do with email that claims to be from your domain but does not pass SPF or DKIM for your domain. The policy can be none (monitor only), quarantine (send to spam) or reject (block). It can also ask for reports so you can see who is sending email as you.

It means monitoring only. Receiving servers can send you reports, but they are not asked to treat failing email any differently, so fake emails from your domain can still reach inboxes. It is a sensible first step, not the finish line.

Either can work. With -all, email from servers not on your list should fail outright. With ~all it is a soft fail, which is fine when your DMARC policy is quarantine or reject, because DMARC then decides what happens. Never use +all, which lets any server send as you.

SPF allows a maximum of 10 DNS lookups when a record is checked. Each include, a, mx, ptr, exists and redirect counts, including those inside the services you include. Go over 10 and SPF breaks with a permanent error, so it can stop vouching for some or all of your email. Remove services you no longer use.

DKIM records are published under a name called a selector, chosen by each email service, and there is no way to list every selector a domain uses. We check the common ones, including the Microsoft 365 and Google Workspace selectors. If you use a service with its own selector, DKIM may still be working.

Yes. Small businesses get spoofed too, and a fake email from your domain to your customers or suppliers can lead to invoice fraud. A DMARC record costs nothing to publish, the work is in checking every service that sends as you, and getting it right also helps your genuine email reach inboxes.

No. With a policy of quarantine or reject, DMARC makes it much harder for criminals to send email using your exact domain. It does not stop lookalike domains, such as one with a letter swapped, or emails from hacked accounts. That is why it works alongside multi-factor authentication, email filtering and staff awareness.

No. The check runs in your browser and looks up public DNS records through Google Public DNS, with Cloudflare as a backup. Nothing you enter is sent to us or stored by us.