Check your domain's SPF, DKIM, DMARC, MX and blacklists in one go.
Type a domain and get one line per record: pass, warning or failure, in plain English. When something fails, you get the exact record to paste into your DNS. Free and unlimited, with no signup.
Works with a domain or a full email address. We read DNS fresh on every run.
3 of 5 checks pass. Fix SPF first: until SPF passes, this domain falls short of the rules Gmail, Yahoo and Outlook set for bulk senders.
Receivers read exactly one SPF record. When they find more, they stop and return a permanent error (RFC 7208), which counts as no SPF at all.
v=spf1 include:_spf.google.com ~all v=spf1 include:secureserver.net -all
Delete both records and publish this one in their place. Your mail is handled by Google Workspace, so include:secureserver.net, GoDaddy's email service, is left out. Add it back only if you also send mail that way.
v=spf1 include:_spf.google.com ~all
Add it as a TXT record with host @ in your DNS, in place of any SPF record already there. This record uses 1 of the 10 DNS lookups SPF allows.
That meets the minimum Gmail and Yahoo ask of bulk senders, but mail that fails is still delivered, so anyone can send as this domain, and you will never hear about it.
v=DMARC1; p=none
Replace it with this record. Your DKIM key is in place, so mail signed with it passes DMARC. Quarantine is safe once the SPF fix above is live. If other services send as this domain, switch DKIM on in each of them first. Reports go to dmarc@trynorthpeak.example: create that address, or change it to one you read.
v=DMARC1; p=quarantine; rua=mailto:dmarc@trynorthpeak.example
Add it as a TXT record with host _dmarc in your DNS, in place of any DMARC record already there.
We can set up your next sending domains with all five checks already passing.
We register the domains, create Google Workspace mailboxes with SPF, DKIM and DMARC in place, and connect them to Emailchaser with warm-up switched on. $6 a mailbox a month, plus $3 setup per mailbox and the domain ($16.59 a year for a .com). Ready in 24 to 48 hours.
The check runs on our server against live DNS and 16 public blocklists (3 for domains, 13 for mail server IPs). A list that does not answer is never counted as clean. Nothing you type is stored.
Each check answers one question Gmail and Outlook ask before they accept your email.
Receiving servers read these records before they choose between inbox, spam and reject, and the MX record decides whether replies come back at all. Each check also has its own page with a deeper report, linked on the right.
| Check | The question it answers | What usually breaks it | Full report |
|---|---|---|---|
| SPF | Is this server allowed to send for the domain? | Two SPF records on one domain, or more than 10 DNS lookups (RFC 7208) | SPF checker → |
| DKIM | Did the domain sign this message, and is it unchanged? | DKIM never switched on at the provider, or a revoked key with an empty p= value | DKIM checker → |
| DMARC | What should happen when SPF and DKIM fail, and does the From domain match? | No record at all, or p=none with no address for reports | DMARC checker → |
| MX | Can this domain receive the replies to your campaign? | No MX record, so every reply bounces | MX lookup → |
| Blacklists | Is the domain, or the server it sends from, on a spam list? | Bounces and complaints that land the domain on a list like SURBL or URIBL | Blacklist check → |
Gmail, Yahoo and Outlook turn away bulk mail from domains that skip these records.
- Gmail: anyone sending 5,000 or more messages a day to Gmail accounts must set up SPF, DKIM and DMARC. Mail that is not authenticated may be marked as spam or rejected with a 5.7.26 error. Google's email sender guidelines
- Yahoo, since February 2024: bulk senders must use both SPF and DKIM, publish a DMARC policy of at least p=none that passes, and keep their spam rate below 0.3%. Yahoo Sender Hub best practices
- Outlook.com, Hotmail and Live, since 5 May 2025: domains sending more than 5,000 emails a day must pass SPF, DKIM and DMARC (at least p=none, aligned with SPF or DKIM). Microsoft rejects mail that does not, with error 550 5.7.515. Microsoft Defender for Office 365 blog, 2 April 2025, updated 29 April 2025
Each source read on 6 October 2026.
Most of the companies you email already enforce DMARC on their own domains.
We read the published records of the same 499 real business domains on every measurement, the kind of companies a cold emailer writes to. On 5 September 2026, 351 of them (70.3%) were at p=reject and only 6 had no DMARC record at all.
Their inbound mail is filtered by Proofpoint at 33.9% of them, Microsoft 365 at 26.1% and Google Workspace at 18.8%. All three check SPF, DKIM and DMARC on the mail they receive, which is why a domain that passes all five checks above is the minimum for cold email, not a bonus.
Source: Emailchaser Inbox Rules Index, 499 business domains, measured 5 Sep 2026 over public DNS. See the DMARC adoption rate.
Each line of the report is a pass, a warning, a failure or a check that could not run.
Pass means the record is there and does its job: one SPF record within the lookup limit, a DKIM key that verifies, a DMARC policy that acts on failures, a mail server that answers, and no listing on any blocklist that answered.
Warning means it works but is weaker than it should be. A DMARC policy of p=none, a 1024-bit DKIM key, an SPF record that ends in ?all, or a DKIM key we could not find under the common names all land here. A warning will not stop your mail today, and it is worth fixing before your volume grows.
Failure means receivers treat the record as missing or broken, or the domain is on a widely used blocklist. Wherever the fix is a record, the report writes it for your domain, with a Copy button and the host name to put it under.
Could not check means DNS did not answer in time. It never counts as a pass. Blocklists follow the same rule one list at a time: before we trust a list's answer about your domain, it has to answer its own test entry. A list that refuses us or is down shows as not checked, and the count of lists checked is only the ones that really answered, out of the 16 we ask.
Fix the records in this order, because each one leans on the one before it.
- MX first. Without a mail server, every reply bounces, and some receivers distrust a domain that cannot receive mail at all.
- Then SPF. One record at the root of the domain, naming the services you send through, within 10 lookups. The SPF checker shows the lookup tree.
- Then DKIM. Switch it on at your email provider and publish the key it gives you. This is the record that survives forwarding, so DMARC leans on it most.
- Then DMARC. With DKIM working, publish p=quarantine with a reports address. Without it, start at p=none.
- Blocklists last, because a listing is a symptom. Stop sending from a listed domain, fix the cause, then ask each list to remove it.
Changes to DNS take from a few minutes to the record's TTL to show up everywhere. Run the check again after each change: it reads DNS fresh every time.
Emailchaser checks all five records in one run, as often as you like.
| SPF, DKIM, DMARC, MX and blacklists in one report | Yes, unlimited, no signup | Email Health Report, with a count of free tests left | Scores SPF, DKIM and DMARC only, no MX or blacklists |
| Finds DKIM without you typing the selector | Yes, 51 common selectors | No, you type the selector | Yes |
| Writes the corrected record for your domain | Yes, ready to paste | Lists the failed tests | Gives a score |
| Sets up sending domains that pass on day one | Yes, $6 a mailbox a month | Sells monitoring, not mailboxes | Sells DMARC monitoring, not mailboxes |
Each rival's free tool was run on 6 October 2026: MXToolbox's Email Health Report and DKIM lookup, and EasyDMARC's Domain Scanner.
A separate domain is the safest place to send cold email from.
If a campaign draws complaints, the domain that sent it takes the hit. Keeping cold email on its own domains means a bad week never touches the domain your customers, invoices and team inboxes rely on.
Every Emailchaser plan connects unlimited mailboxes, and each one can run on a ramp: 5 emails a day in week one, 5 more each week, up to 50. Mailboxes we set up for you on new domains start with it switched on. If you would rather not touch DNS at all, we set the domains up for you at $6 a mailbox a month, with SPF, DKIM and DMARC done. Need to send this week? Warmed-up accounts sit on domains set up more than 12 weeks ago: $6 a mailbox a month plus a one-time $16.79 domain fee, with no warm-up wait.
Common questions about domain health checks
What does a domain health check test?
Five things a receiving server looks at before it accepts your email: the SPF record (which servers may send for you), the DKIM key (proof you signed the message), the DMARC policy (what to do when those fail), the MX records (where replies go) and whether the domain or its own mail server is on a public blocklist.
What is a good SPF record for cold email?
One record, at the root of the domain, that names only the services you actually send through and ends in ~all or -all. A domain on Google Workspace needs just v=spf1 include:_spf.google.com ~all. Every extra include costs DNS lookups, and the record fails outright past 10.
Why does the check find no DKIM key when I set one up?
DKIM keys live under a name called a selector, and we try the 51 most common ones. If your provider uses a custom selector, open the DKIM checker and type it in, and we will read that key directly. You can find your selector in the s= value of the DKIM-Signature header of any email you sent.
Should my DMARC policy be none, quarantine or reject?
Start at p=none with a reports address only if you are not sure who sends as your domain. Once DKIM is on for everything you send, move to p=quarantine. A dedicated cold email domain that only sends through one provider with DKIM on can usually start at quarantine.
My domain is on a blocklist. What do I do?
Stop sending from it, find the cause (usually bounces from an unverified list, or a jump in volume), then request removal through the link we show next to each listing. Removal without fixing the cause gets you listed again.
Why does a blocklist show as not checked?
Some lists refuse queries they think come from a shared resolver, and some are simply down for a while. Our check asks every list for its own test entry first, and a list that refuses, fails or does not recognise that entry is marked not checked and left out of the count. We never report a list that did not answer as clean.
Is this check free?
Yes. It is free and unlimited, with no signup and no email address. The only cap is 20 checks a minute from one connection, which stops scripts, not people.
Do you keep the domains I check?
No. The domain is used to run the lookups and is gone when the answer comes back. It is not saved, and it is not sent to our analytics.
More free tools for your sending setup
Send cold email from domains that pass all five checks.
Every plan includes warm-up, follow-ups and unlimited email accounts, from $47 a month.
Start my free trial7-day free trial, $0 today