Free • Instant • No sign-up
Free DMARC and SPF checker
Could a criminal send an email that looks like it came from your business? Enter your domain to test its SPF, DKIM and DMARC records, and get a plain-English result with what to fix.
Plain English
SPF, DKIM and DMARC: what they actually do
Email was never designed to check who a message is really from. These three records, published in your domain’s DNS, fill that gap. You need all three working together.
Who is allowed to send
A list of the mail servers and services allowed to send email for your domain, such as Microsoft 365, your accounts software or your newsletter tool.
Like a guest list on the door.
Proof it was not tampered with
A digital signature each of your email services adds to the emails it sends, once DKIM is switched on. The receiving server checks it against a public key in your DNS to confirm the email is genuine and unchanged.
Like a tamper-evident seal.
What to do with fakes
Tells receiving servers what to do when an email claiming to be from you does not pass SPF or DKIM for your domain: let it through, send it to spam or reject it. It can also send you reports.
Like instructions to the bouncer.
Why it matters
A spoofed email from your domain is a gift to fraudsters
If your domain has no DMARC policy, or one set to none, a criminal can send an email that shows your real address in the From line, and many inboxes will accept it. That is how a lot of invoice fraud starts: a convincing email to your customers or suppliers saying your bank details have changed.
Our guide to invoice fraud and business email compromise explains how these scams work, and our free phishing test shows what to look out for.
Getting these records right also helps your genuine email. The big email providers now check them, so invoices, quotes and newsletters sent from badly set up domains are more likely to land in spam.
How to fix a bad result
Getting to DMARC reject without breaking your email
- List everything that sends email as youMicrosoft 365 or Google Workspace, plus your accounts software, CRM, website forms, newsletter tool and anything else that sends from your domain.
- Fix SPFKeep one SPF record that includes every one of those services, stays within 10 DNS lookups and ends in
-allor~all. - Turn on DKIM everywhereSwitch on DKIM signing in Microsoft 365 or Google Workspace, and in each other service that sends for you.
- Publish DMARC at p=none with reportsAdd a record such as
v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.co.ukand read the reports for a few weeks to find anything you missed. - Move to quarantineWhen your genuine email is passing, change to
p=quarantine, so failing email goes to spam. - Finish at rejectThen move to
p=reject, the policy the NCSC recommends. Keep watching the reports for a few weeks afterwards, and whenever you add a new service that sends email.
Do not jump straight to reject. If a service that sends email for you is missing from SPF or DKIM, its emails will be blocked too. Go step by step and watch the reports.
Free • No obligation • Senior engineer
Want us to fix your email security?
Tell us your domain and a senior engineer will look at your SPF, DKIM and DMARC records with you, find every service that sends email as you, and give you a safe plan to get to DMARC reject without blocking your own email.
What you get
- Your SPF, DKIM and DMARC records checked
- Every service that sends as you identified
- A step-by-step plan to DMARC reject
- Microsoft 365 email security reviewed
If it is urgent, call us on 01903 255 159.
FAQ
DMARC, SPF and DKIM: common questions
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving mail servers what to do with email that claims to be from your domain but does not pass SPF or DKIM for your domain. The policy can be none (monitor only), quarantine (send to spam) or reject (block). It can also ask for reports so you can see who is sending email as you.
It means monitoring only. Receiving servers can send you reports, but they are not asked to treat failing email any differently, so fake emails from your domain can still reach inboxes. It is a sensible first step, not the finish line.
Either can work. With -all, email from servers not on your list should fail outright. With ~all it is a soft fail, which is fine when your DMARC policy is quarantine or reject, because DMARC then decides what happens. Never use +all, which lets any server send as you.
SPF allows a maximum of 10 DNS lookups when a record is checked. Each include, a, mx, ptr, exists and redirect counts, including those inside the services you include. Go over 10 and SPF breaks with a permanent error, so it can stop vouching for some or all of your email. Remove services you no longer use.
DKIM records are published under a name called a selector, chosen by each email service, and there is no way to list every selector a domain uses. We check the common ones, including the Microsoft 365 and Google Workspace selectors. If you use a service with its own selector, DKIM may still be working.
Yes. Small businesses get spoofed too, and a fake email from your domain to your customers or suppliers can lead to invoice fraud. A DMARC record costs nothing to publish, the work is in checking every service that sends as you, and getting it right also helps your genuine email reach inboxes.
No. With a policy of quarantine or reject, DMARC makes it much harder for criminals to send email using your exact domain. It does not stop lookalike domains, such as one with a letter swapped, or emails from hacked accounts. That is why it works alongside multi-factor authentication, email filtering and staff awareness.
No. The check runs in your browser and looks up public DNS records through Google Public DNS, with Cloudflare as a backup. Nothing you enter is sent to us or stored by us.


