Email DNS Record Lookup (MX, DMARC, DKIM, SPF)
MX, DMARC, DKIM and SPF records in one report.
About the Email Record Lookup tool
Email deliverability and anti-spoofing depend on four kinds of DNS record. MX records route inbound mail, SPF lists the servers allowed to send for the domain, DKIM publishes the public keys that verify message signatures, and DMARC tells receivers what to do when SPF and DKIM fail.
DKIM keys live under a selector that only the sender knows. Enter the selector from the s= tag of a message's DKIM-Signature header for a definitive answer, or leave it blank and we will try a list of common selectors.
Frequently asked questions
What DMARC policy should I use?
Start with p=none and a rua= reporting address, review the reports, then move to quarantine and finally reject once legitimate senders pass.
Why is DKIM not found?
DKIM uses selectors chosen by each mail platform. If none of the common selectors match, enter the selector from a real message header.
What is the SPF 10-lookup limit?
SPF evaluation may trigger at most 10 DNS-querying terms (include, a, mx, ptr, exists, redirect). Exceeding it causes a permerror and SPF failure.