Mail routing
See whether the domain has active mail servers and which provider appears to handle them.
Check the records behind your website and email. Find missing protection, understand what is wrong, and get a practical next step.
Enter a root domain. We query public DNS records only.
Your report will appear here.
Checking public records…
Live technical checks paired with guidance that a small business can actually use.
See whether the domain has active mail servers and which provider appears to handle them.
Find the SPF policy, includes, lookup pressure, and common configuration mistakes.
Understand whether spoofed mail is monitored, quarantined, or rejected.
Start with basic routing, then inspect authentication. MX records show where inbound mail should go. SPF lists permitted outbound infrastructure. DMARC tells receiving systems how to evaluate aligned SPF or DKIM results and what handling policy the domain requests.
Your mail provider’s setup instructions are the authoritative source for hostnames and values. A copied SPF include or DMARC example may be wrong for your providers, reporting addresses or enforcement stage.
DNS responses are cached. The time-to-live value and resolver behavior influence how quickly a change becomes visible. Check the authoritative provider, wait through the relevant cache window and test again before making repeated changes.
Read the complete MX, SPF and DMARC guide →
Last updated 6 September 2026. Results are diagnostic observations from public DNS, not a guarantee of delivery or security.
No. It shows published routing information. Mailboxes, server availability, filtering, account configuration and other conditions also affect delivery.
A domain should publish a single applicable SPF policy. Multiple SPF TXT policies can produce a permanent error; consolidate legitimate mechanisms carefully.
No. DMARC evaluates alignment using SPF and/or DKIM authentication results. A dependable setup normally configures the underlying authentication first.
Browsers cannot query DNS records directly in the same way as a DNS client, so the checker requests public DNS answers from a resolver service. Enter only public domain names.
No. The score summarizes a limited set of visible DNS checks. It cannot assess account security, DKIM signing for every sender, message content or recipient filtering.