SPF, DKIM & DMARC Checker

Check a domain's email authentication records and find out why its mail goes to spam.


SPF, DKIM & DMARC Checker

Mail providers such as Gmail, Outlook and Yahoo check three DNS records before they trust an email: SPF lists the servers allowed to send for your domain, DKIM adds a signature that proves a message was not changed, and DMARC tells receivers what to do when those checks fail. Missing or broken records are one of the most common reasons business email lands in spam. This checker reads all three, plus your MX records, and explains what to fix.

How to use SPF, DKIM & DMARC Checker

  1. Enter the domain you send email from, such as example.com.
  2. If you know your DKIM selector, enter it; otherwise the checker tries the selectors used by the common email services.
  3. Click Check records and read each section. Anything marked Problem or Improve comes with a short explanation of the fix.

When it comes in handy

  • Finding out why your emails go to spam or are rejected.
  • Checking the setup after moving to Google Workspace, Microsoft 365 or a new email service.
  • Meeting the Gmail and Yahoo requirements for bulk senders, which include SPF, DKIM and DMARC.

Frequently asked questions

Where do I find my DKIM selector?
Open an email you sent from the domain, view the original message or headers, and find the DKIM-Signature line. The value after s= is the selector.
What does "too many DNS lookups" mean?
SPF allows at most 10 DNS lookups, counting every include:, a, mx and redirect, including those inside the included records. Above 10, SPF fails for every message. Remove services you no longer use, or replace some includes with ip4:/ip6: ranges.
Should I use p=reject straight away?
No. Start with p=none and a rua= address to receive reports, check that all your real mail passes, then move to p=quarantine and finally p=reject.

Choose which cookies SEOpeck may use. You can change this at any time from "Cookie settings" at the bottom of every page.