Email Authentication Check: SPF, DKIM, DMARC, DNSSEC
When company mail lands in customer spam folders, the culprit is rarely the content; it is usually a missing DNS record. SPF declares which servers may send on your behalf, DKIM signs messages, DMARC sets the policy. If any piece is missing, the receiving filter bins the message. This tool queries the SPF, DKIM, DMARC, and DNSSEC records of the domain you type and lists the results on the page. Leave the DKIM selector empty and common selectors are tried one by one. The lookup runs on the server, results appear on screen, nothing is stored.
Step by step
- Type the domain to audit, bare form like example-company.com, no www.
- Enter the DKIM selector if you know it; leave it empty and common selectors are tried automatically.
- Start the check and wait for results; it usually takes a few seconds.
- Read the authorized senders on the SPF line and the policy on the DMARC line.
- Check which selectors answered in the DKIM section and the signature state in the DNSSEC section.
- Fix missing or wrong records in your domain panel, then run the check again.
Example scenario
Murat runs IT at a logistics firm and keeps hearing complaints: quote emails land in spam. He types the company domain into the tool and leaves the selector blank. The result shows an SPF record but no DMARC at all, and only an ancient selector answers for DKIM. He adds a DMARC record in the domain panel, registers a fresh selector, and re-runs the check an hour later to see every line come back healthy. The complaints stop that same week.
Check your result
Confirm the SPF record starts with v=spf1 and covers every service that sends your mail. Check the DMARC policy carries one of none, quarantine, or reject; start with none if you have no record yet. In the DKIM section verify your current selector answers and stale ones are cleaned up. If DNSSEC shows unsigned, consider enabling signing at your registrar. After changes, allow some propagation time and re-run the check.
Frequently asked questions
What is a DKIM selector and where do I find it?
The selector is the DNS name of your signing record, printed in your mail provider admin panel. Leave it empty if unknown; the tool tries common selectors one by one. If nothing answers, enter the value from your panel.
I have no DMARC record; is that a problem?
Mail keeps flowing, but forged messages can easily go out in your name. Start with a monitoring-only none policy, watch the reports, then step up to quarantine.
How many servers can an SPF record hold?
The DNS lookup limit means your record should not trigger more than ten lookups. If you use many services, flatten and simplify; the tool shows the raw record so the bloat is visible.
What does the DNSSEC result mean?
It shows whether your domain answers carry signatures. Unsigned does not stop mail flow, but one anti-forgery layer is missing. You can ask your operator to enable signing.
Are my queried domains recorded?
No. The lookup happens live, results display on screen, nothing is stored. You may audit other domains too; these are public DNS facts.
Open the tool: Email Auth Check →
Keep an original copy before processing your file. Examples are illustrative; results depend on your document.