Home About Services Projects Blog Contact Free Tools
Free tool

SPF, DKIM & DMARC Checker + Record Generator

If your e-mails land in spam or Gmail shows “via” or a warning, your domain’s e-mail authentication is usually missing or wrong. Enter your domain to test MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI and blocklists in seconds – then use the generator to create correct SPF and DMARC records for Google Workspace, Microsoft 365, Zoho, Hostinger or cPanel.

Free · no sign-up · checks MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI and blocklists

SPF & DMARC record generator

Choose your e-mail provider and the services that send e-mail for you – the records update instantly. Add them as TXT records in your DNS (hPanel, cPanel, Cloudflare, GoDaddy…).

Also sends e-mail for me

What the e-mail checker tests

MX records

Which servers receive your e-mail and which provider you use (Google, Microsoft, Zoho, Hostinger…).

SPF

Is there exactly one SPF record, does it end with -all or ~all, and does it stay under the 10 DNS-lookup limit?

DKIM

We look for DKIM keys on 30+ common selectors (google, selector1/2, hostingermail, k1, s1…).

DMARC

Your policy (none, quarantine, reject), the percentage and where reports are sent.

MTA-STS & TLS-RPT

Encrypted delivery between mail servers and TLS failure reports.

Blocklists

Spamhaus and SpamCop listings for your domain and mail-server IPs.

Quick answer

E-mails go to spam mainly when the domain has no valid SPF, DKIM and DMARC. You need one SPF TXT record listing every service that sends for you (ending in ~all or -all), DKIM enabled at your e-mail provider, and a DMARC record such as v=DMARC1; p=quarantine; rua=mailto:you@yourdomain.com. Since 2024 Gmail and Yahoo require all three for bulk senders.

How to use it

  1. Type your domain or any e-mail address on it and press Check e-mail setup.
  2. Fix every red item first: missing SPF, DKIM or DMARC, multiple SPF records, or more than 10 SPF lookups.
  3. Use the generator to create the correct records, add them in your DNS, wait 15–60 minutes and check again.

SPF, DKIM and DMARC in plain words

  • SPF lists the servers allowed to send e-mail for your domain (one TXT record starting with v=spf1).
  • DKIM adds a digital signature to each e-mail; the public key is published in DNS under selector._domainkey.
  • DMARC tells Gmail, Outlook and others what to do with e-mails that fail SPF/DKIM – and sends you reports (TXT record on _dmarc).

The most common mistakes

MistakeEffectFix
Two SPF recordsSPF fails completely (permerror)Merge them into one record with several include: parts.
More than 10 DNS lookupsSPF fails for many receiversRemove unused services or use flattened IPs.
+all or no allAnyone can send as youEnd with ~all or -all.
DKIM not enabledMessages lack a signature, more spamTurn on DKIM in your provider’s admin panel and publish the key.
No DMARCGmail/Yahoo may reject bulk mail; spoofing is easyStart with p=none plus reports, then move to quarantine.

Safe DMARC roll-out

  1. Publish v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com and read the reports for 1–2 weeks.
  2. Make sure every real sender (website forms, newsletters, invoices, CRM) passes SPF or DKIM.
  3. Move to p=quarantine, then to p=reject for full protection against spoofing.

Website forms going to spam? WordPress sends mail through PHP by default, which fails SPF/DKIM on most hosts. Send through your real mailbox with SMTP (WP Mail SMTP or similar) using the same domain. I set this up as part of website maintenance and business IT setup.

Frequently asked questions

Why are my e-mails going to spam?

Usually because SPF, DKIM or DMARC is missing or wrong, the sending IP or domain is on a blocklist, or messages are sent from a website without SMTP. Run this checker and fix the red items first.

Can I have two SPF records?

No. A domain must have only one SPF record. Two records make SPF fail. Merge them into one, for example v=spf1 include:_spf.google.com include:servers.mcsv.net ~all.

What is the 10 DNS lookup limit in SPF?

SPF allows at most 10 DNS lookups (include, a, mx, ptr, exists, redirect), counting nested includes. Above 10, SPF returns an error and fails. The checker counts them for you.

Which DMARC policy should I use?

Start with p=none and a reporting address to see who sends e-mail as your domain, then move to p=quarantine and finally p=reject once all legitimate senders pass SPF or DKIM.

Why can’t the checker find my DKIM?

DKIM keys are stored under a selector name chosen by your provider. We test 30+ common selectors; if yours uses a custom one, DKIM may exist but not be found. Check your provider’s admin panel for the selector name.

Want an expert to handle it?

I’m Eslam Abdullah – WordPress developer and web security specialist with 8+ years and 450+ projects. Send me your result on WhatsApp for a free consultation.

Chat on WhatsApp

More free tools

All free tools →