STRATEDGE CONSULTING

Free tool

SPF, DKIM and DMARC test for your domain

Enter the domain that sends your emails. The test reads its DNS the way Gmail, Yahoo and Outlook do before accepting a message: receiving servers, SPF, DKIM signature, DMARC policy and extras. Each point comes with the fix to make and the official page it rests on.

It follows “s=” in the DKIM-Signature header of an email you sent. Without it, the test tries the selectors of the most common sending services.

What the test checks

SPF

The list of servers allowed to send for your domain, its includes and the number of DNS lookups, which RFC 7208 caps at ten.

DKIM

The public key used to verify your messages' signature, and its size: 1,024 bits minimum, 2,048 recommended by RFC 8301.

DMARC

The policy applied to failing messages, the report address, and the parameters removed by RFC 9989, published in May 2026.

Mailbox provider requirements

Gmail and Yahoo have required SPF, DKIM and DMARC from bulk senders since 2024; Outlook has required them since 5 May 2025 above 5,000 emails a day.

What the DNS does not show

The test reads what is published, not your sending. Three requirements are checked in the messages themselves: sender domain alignment with SPF or DKIM, one-click unsubscribe for marketing emails (RFC 8058), and the complaint rate, which Gmail asks to keep below 0.1% and never let reach 0.3%. Gmail's Postmaster Tools show them for your domain.

Frequently asked questions

The strict requirements target bulk senders, close to 5,000 messages a day to Gmail addresses. Below that, Gmail still asks every sender for SPF or DKIM, and the three mechanisms remain the surest way to reach the inbox and stop others spoofing your domain.

Go further