SPF / DKIM / DMARC Checker
Email Authentication Diagnostic
Sender
Outbound mail
SPF
Who can send?
DKIM
Was it signed?
DMARC
Does it align?
Receiving System
Inbox decision
The domain (and optional selector) you enter is submitted to IT KORR's server to perform publicly available DNS lookups — no mailbox is accessed, no email is sent, no SMTP authentication occurs. IT KORR's own domains and infrastructure cannot be scanned with this tool.
Understanding the Results
Three Standards. One Authentication Layer.
Analyze SPF, DKIM, and DMARC records, authentication policy, DKIM key strength, SPF dependencies, and enforcement gaps — live from DNS, no account required. SPF, DKIM, and DMARC work in combination: a gap in any one weakens the others.
SPF
Sender Policy Framework
A DNS TXT record listing which IP addresses and mail servers are authorized to send email from your domain.
Without SPF, any server can send email appearing to come from your domain. This is the most basic layer of email spoofing protection.
DKIM
DomainKeys Identified Mail
A cryptographic signature added to outgoing email that receiving servers can verify against a public key published in DNS.
DKIM protects message integrity — verifying that content was not altered in transit and that the sending domain can be authenticated cryptographically.
DMARC
Domain-based Message Authentication
A policy record telling receiving servers what to do when SPF or DKIM checks fail: monitor, quarantine, or reject.
DMARC is the enforcement layer. Without it, SPF and DKIM results are visible but no action is taken on failures.
What To Look For
Five Indicators of Email Authentication Maturity
SPF Hard Fail (-all)
Prefer "-all" (hard fail) over "~all" (soft fail) once your authorized sending sources are fully inventoried. Hard fail gives receiving servers a clear directive to reject unauthorized messages.
SPF Include Count
SPF records have a 10 DNS lookup limit. Too many nested includes cause SPF to fail with a "permerror". This checker recursively walks your SPF include chain and shows an estimated lookup count.
DKIM Selector Visibility
If DKIM is not detected, this does not mean it's absent — it may use a non-standard selector. Check your email provider's admin portal to confirm DKIM is enabled and note the selector name.
DMARC Policy Enforcement
"p=none" provides visibility but no protection. "p=quarantine" routes failing messages to spam. "p=reject" prevents delivery entirely. The goal is "p=reject" with a monitoring address configured.
DMARC Reporting Address
The "rua=" tag sends aggregate reports to a specified address. These reports identify sources sending email from your domain — both legitimate and unauthorized. Without them you are flying blind.
Operational Impact
Email Authentication Affects More Than Deliverability
Properly configured email authentication is an operational governance requirement — not just an IT task.
Regulatory Compliance
HIPAA, NIST SP 800-171, CMMC, and SOC 2 all include requirements around email security controls. Missing DMARC enforcement is a documented finding in many compliance assessments — particularly for healthcare, legal, and government contractor organizations.
Business Email Compromise Prevention
BEC (Business Email Compromise) attacks often involve spoofing your domain to impersonate executives or finance staff. DMARC enforcement at "p=reject" directly prevents successful spoofing of your exact domain by external parties.
Microsoft 365 Deliverability
Microsoft 365's spam filtering uses SPF, DKIM, and DMARC alignment signals to score inbound and outbound messages. Misconfigured records increase the probability that legitimate outbound mail is flagged as spam by recipient organizations.
Client and Partner Trust
Recipients increasingly receive warnings when email from a domain lacks authentication. Some organizations filter or reject unauthenticated email by policy. Authentication is now a baseline expectation for professional communication.
Related Operational Resources
Want a broader email-domain security review? Add BIMI, MTA-STS, and TLS-RPT to the picture.
Broader DNS diagnostic including MX and NS records alongside email authentication.
Inspect certificate validity, expiration, and TLS configuration.
Ongoing Microsoft 365 governance including email authentication and Defender configuration.
Align email security posture with HIPAA, SOC 2, and NIST requirements.
Why SPF and DKIM passing does not mean DMARC passes — how alignment actually connects the three standards.
How SPF, DKIM, and DMARC gaps create compliance findings and spoofing exposure beyond deliverability.
FAQ
Common Questions
What is SPF and why does it matter?
SPF (Sender Policy Framework) is a DNS record that lists which mail servers are authorized to send email on behalf of your domain. Without it, any server can send email appearing to come from your domain. For Microsoft 365, SPF must include the Office 365 sending infrastructure and any additional approved sending services.
Why can't DKIM always be verified?
DKIM signatures are tied to specific "selectors" — custom identifiers your mail provider assigns. By default this tool checks 13 common selectors used by major providers. If your provider uses a non-standard selector, DKIM may be active but not detected — a "not found" result on common selectors does not prove DKIM is unconfigured. Enter your exact selector in the optional field for an authoritative, user-provided-selector lookup.
Where do I find my DKIM selector?
Check your email provider's admin portal — Microsoft 365 (Exchange Admin Center, under DKIM settings for the domain), Google Workspace (Admin Console, under Apps → Gmail → Authenticate email), or your provider's DNS setup documentation. The selector is the value immediately before "._domainkey" in the DKIM DNS record name.
Does having SPF and DKIM configured mean DMARC passes?
Not automatically. DMARC additionally requires alignment — the domain that SPF or DKIM actually authenticated must match (or be a subdomain of) the visible "From" address domain. A domain can have valid SPF and DKIM records in DNS and still fail DMARC on a specific message if that message's authenticated domain doesn't align with its From header.
Does this tool send an email or access my mailbox?
No. This is a DNS-only diagnostic — it queries publicly available DNS TXT records for SPF, DKIM, and DMARC. It never sends email, never connects to an SMTP server, and never requires or accepts Microsoft 365, Google Workspace, or mailbox credentials of any kind.
Can this tool guarantee my email will be delivered or land in the inbox?
No. Strong SPF, DKIM, and DMARC configuration is one of many factors that influence deliverability, but this tool cannot guarantee inbox placement, deliverability, or that any specific message will pass authentication at a receiving server — spam filtering, sender reputation, and content also play a role.
What DMARC policy should I use?
Start with "p=none" for monitoring with a "rua=" reporting address. Review aggregate reports for 30–60 days to identify all legitimate sending sources. Move to "p=quarantine" once confident, then to "p=reject" for full enforcement. Do not rush to "p=reject" — a misconfigured enforcement policy will reject legitimate mail.
How often should I review these records?
Review after any email provider change, new third-party sending service, or domain migration. For compliance-aware organizations, quarterly reviews are a reasonable baseline. Changes to email configuration should always include verification of SPF, DKIM, and DMARC records.
What happens when SPF and DMARC conflict?
DMARC evaluates both SPF and DKIM results. A message passes DMARC if it passes either SPF or DKIM in alignment with the From domain. If both fail, DMARC enforcement applies the configured policy (none, quarantine, or reject). Having both SPF and DKIM configured provides redundancy.
Does this affect Microsoft 365 deliverability?
Directly. Microsoft 365 email filtered as spam by recipient servers is often due to missing or misconfigured SPF, DKIM, or DMARC. Exchange Online Protection also uses these signals internally. Properly configured email authentication reduces false positive spam filtering and improves delivery rates.
Operational Support
Need help configuring email authentication?
IT KORR can audit your email security posture and coordinate SPF, DKIM, and DMARC implementation across your current providers — no migration required.
No commitment required — we respond within one business day.