Find out in 60 seconds whether anyone can send email pretending to be your domain. Read your SPF, DKIM and DMARC records, know what good looks like, and fix the gaps.
1. SPF: who may send as you
SPF lists the servers allowed to send mail for your domain. It should end in -all (hard fail). ~all (soft fail) or ?all lets spoofed mail through more often.
dig +short TXT example.com | grep spf
# good: "v=spf1 include:_spf.google.com -all"
2. DKIM: the signing key
DKIM signs every message so receivers can prove it was not altered. The record lives at <selector>._domainkey.yourdomain. The selector depends on your provider: Google Workspace uses google, Microsoft 365 uses selector1 and selector2.
dig +short TXT google._domainkey.example.com
# good: "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
3. DMARC: what happens to fakes
DMARC tells receivers what to do when SPF and DKIM fail, and where to send reports. p=none only monitors. Move to p=quarantine, then p=reject once the reports show your real senders pass.
dig +short TXT _dmarc.example.com
# good: "v=DMARC1; p=reject; rua=mailto:dmarc@example.com"
Skip the terminal: free checker
The DeciusAc email tools read all three records and grade them, no signup. For blacklist checks use the security tools page.
Fixing what you find
No SPF: add one TXT record listing your mail provider’s include and ending in -all. No DKIM: turn on signing in your mail provider’s admin console and publish the record it gives you. No DMARC: start with v=DMARC1; p=none; rua=mailto:you@yourdomain, read the reports for two weeks, then tighten to reject.
Last updated October 2026.