Email Checker & Deliverability Tools
Check your domain's email configuration - SPF, DMARC, DKIM, MX, BIMI, MTA-STS and TLS-RPT - and analyze raw message headers. Stop spoofing, improve inbox placement, and pass authentication.
One report covers SPF, DMARC, DKIM, MX, BIMI, MTA-STS and TLS-RPT, or pick a single check below.
Authentication & anti-spoofing
The core records mailbox providers (Gmail, Outlook, Yahoo) check before delivering your mail.
SPF Checker
Validate your Sender Policy Framework record and authorized senders.
Open tool →DMARC Checker
Inspect your DMARC policy (p=), alignment and reporting addresses.
Open tool →DKIM Checker
Look up DKIM public keys by selector and verify the signature setup.
Open tool →MX Checker
See which mail servers accept email for the domain, with priorities.
Open tool →BIMI Checker
Check the BIMI record that shows your logo next to authenticated mail.
Open tool →Transport security & diagnostics
Advanced records and raw-header analysis for encrypted, reportable, debuggable email.
MTA-STS Checker
Verify the policy that enforces TLS encryption for inbound mail.
Open tool →TLS-RPT Checker
Check SMTP TLS reporting so you get notified about delivery failures.
Open tool →Email Header Analyzer
Paste raw headers to trace routing and read SPF/DKIM/DMARC results.
Open tool →Email Headers Guide
Learn how to read Received, Authentication-Results and more.
Open tool →Record generators
Build a correct record from scratch, then verify it with the matching checker.
SPF Record Generator
Pick your providers and IPs and get a valid v=spf1 record with a live lookup count.
Open tool →DMARC Record Generator
Choose a policy and reporting and get a valid v=DMARC1 record with safe rollout guidance.
Open tool →Why email authentication matters
When you send email, receiving servers decide whether to deliver, junk, or reject it based on how well your domain is authenticated. Three records do most of the work: SPF lists the servers allowed to send for your domain, DKIM cryptographically signs each message, and DMARC tells receivers what to do when SPF or DKIM fail - and where to send reports. Together they stop attackers from spoofing your domain and help legitimate mail reach the inbox.
Beyond the basics, MX records route inbound mail, BIMI can display your brand logo next to authenticated messages, and MTA-STS and TLS-RPT enforce and report on encrypted transport. Use the checks above to confirm each record is present and correctly formatted, then paste a real message into the Email Header Analyzer to see how a mailbox provider actually evaluated your mail.