Scaling Labs
Blog / Free tool
Free tool

Verify SPF, DKIM and DMARC on your domain

Not sure whether your domain is set up correctly, whether you can send email from it and whether it lands in spam? Enter the domain and we check that your DNS records are configured the way they should be, and what to fix.

Since February 2024 Google and Yahoo require SPF, DKIM and DMARC from bulk senders. Without those three records cold email lands in spam regardless of the copy, and a new domain burns out within a week. The tool queries DNS live, guesses nothing and stores nothing.

We check the domain, not the mailbox. If you send from several domains, check each one. Enter a DKIM selector only if your provider uses something other than the common google, selector1, selector2, k1 or default.

What the results mean

SPF tells receiving servers who may send on behalf of the domain. The most common errors are a missing record, two records at once, and exceeding the ten-lookup limit, which invalidates the whole record. The record should end with ~all or -all.

DKIM is a cryptographic signature on every message. The public key sits in DNS under the selector name. If we find no key under common selectors, DKIM is usually not enabled at the mail provider, which lowers trust in every email.

DMARC ties both together and says what to do with mail that fails. Policy none enforces nothing but satisfies Google's requirement. Move to quarantine or reject after a few weeks of reading reports.

The fix order we use with clients

Not everything at once. This order minimises the risk of breaking something mid-campaign.

  • DKIM first, because without it DMARC fails for most providers anyway.
  • Then SPF: one record, every sending tool as an include, ~all at the end, under ten lookups.
  • Finally DMARC from p=none with a reporting address, quarantine after 2-4 weeks.
  • After each change wait up to an hour for propagation and check again.

What this tool does not check

DNS records are a precondition, not a guarantee. The tool cannot see domain and mailbox reputation, warm-up, list quality or the copy itself. Check the copy in our spam checker; the rest is covered in our deliverability articles.

Frequently asked questions

Is p=none enough for DMARC?
To satisfy Google and Yahoo, yes. To protect the domain, no, because none blocks nothing. Start with none plus a reporting address, then move to quarantine after a few weeks.
Why can't you find my DKIM?
We test a few dozen common selectors. If your provider uses another one, enter it in the selector field. You will find the selector name in your mail provider's DKIM settings.
How many DNS lookups can SPF have?
At most ten in total, counting every include, a, mx, ptr, exists and redirect, including those nested inside other providers' includes. The eleventh lookup invalidates the whole record.
Do you store the domains you check?
No. Queries go to DNS on the fly and are not stored. You only leave an address if you want to unlock the fix instructions.
Newsletter

A new playbook every two weeks for more meetings from prospecting

Strategies from the campaigns we run right now, straight to your inbox.

Unsubscribe in one click.

Albert Zuszman
Albert ZuszmanFounder, Scaling Labs

Albert Zuszman runs Scaling Labs, a B2B prospecting agency based in Warsaw. He has spent years building cold email and cold calling campaigns for B2B companies, PE funds and teams entering the Polish market. He writes about what works in real projects, with campaign numbers.