Security

Find out in 60 seconds whether anyone can send email pretending to be your domain. Read your SPF, DKIM and DMARC records, know what good looks like, and fix the gaps.

▶ Watch the demo: check SPF, DKIM and DMARC in 60 seconds (21 sec)Watch on YouTubeSubscribe

1. SPF: who may send as you

SPF lists the servers allowed to send mail for your domain. It should end in -all (hard fail). ~all (soft fail) or ?all lets spoofed mail through more often.

dig +short TXT example.com | grep spf
# good: "v=spf1 include:_spf.google.com -all"

2. DKIM: the signing key

DKIM signs every message so receivers can prove it was not altered. The record lives at <selector>._domainkey.yourdomain. The selector depends on your provider: Google Workspace uses google, Microsoft 365 uses selector1 and selector2.

dig +short TXT google._domainkey.example.com
# good: "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."

3. DMARC: what happens to fakes

DMARC tells receivers what to do when SPF and DKIM fail, and where to send reports. p=none only monitors. Move to p=quarantine, then p=reject once the reports show your real senders pass.

dig +short TXT _dmarc.example.com
# good: "v=DMARC1; p=reject; rua=mailto:dmarc@example.com"

Skip the terminal: free checker

The DeciusAc email tools read all three records and grade them, no signup. For blacklist checks use the security tools page.

Fixing what you find

No SPF: add one TXT record listing your mail provider’s include and ending in -all. No DKIM: turn on signing in your mail provider’s admin console and publish the record it gives you. No DMARC: start with v=DMARC1; p=none; rua=mailto:you@yourdomain, read the reports for two weeks, then tighten to reject.

Last updated October 2026.