Skip to content
DNS SETUP GUIDE · TOOL COMING SOON

Sending-domain checker

See what your public authentication records say—and what to check next.

Which domain should I enter?

Start with the domain in your email’s visible From address to inspect DMARC. SPF applies to the envelope/return-path domain, which may differ; check it separately. DKIM uses the signing domain and selector from the message’s DKIM-Signature header.

For a selector of mail1 and a signing domain of your-app.com, the tool looks for mail1._domainkey.your-app.com. Leave the selector blank if you do not know it; a domain alone cannot reliably reveal all DKIM keys.

What this check covers

The checker looks up public TXT records, identifies SPF records, checks basic DMARC policy structure and organizational-domain fallback, and looks for a DKIM public key at a supplied selector. A DNS timeout is shown as unavailable, not missing.

It does not perform recursive SPF evaluation, verify a message signature, check DMARC report destination authorization, or inspect provider account readiness. A found record is configuration evidence, not a universal deliverability score.

DNS is cached. After changing records, allow for your TTL and resolver caching before expecting every lookup to show the new value.

Use the results to make a specific change

Compare each returned name and value with your provider’s configuration instructions. Preserve existing mailbox MX records and stronger security policies. This tool is read-only and never changes DNS.

Follow the authentication setup and troubleshooting guide →

Inspect the reported results on a received message →