SPF, DKIM & DMARC check
Email authentication: SPF syntax and the 10-lookup limit, DKIM selectors and key length, the DMARC policy and reporting – plus BIMI, MTA-STS and TLS-RPT.
Want to focus on one area? Each of these free tests digs into a single topic in depth – or run the full domain security check to cover everything in one go.
Email authentication: SPF syntax and the 10-lookup limit, DKIM selectors and key length, the DMARC policy and reporting – plus BIMI, MTA-STS and TLS-RPT.
TLSA records (3 1 1), the DNSSEC prerequisite and whether the published TLSA data matches the certificate your MX hosts actually serve.
Zone signing, the DS record at the registrar, recommended algorithms (RFC 9904), signature lifetimes, NSEC3 and automatic DS maintenance.
HSTS, Content-Security-Policy quality, clickjacking protection, cookie flags and CORS – plus what the module checks beyond the classic headers.
The website's HTTPS: certificate chain & trust, validity and hostname, key strength, TLS versions (1.0–1.3), cipher suites & forward secrecy, HSTS and the HTTP→HTTPS redirect.
The _mta-sts record and the HTTPS policy file, its mode and max_age, whether the mx list matches your real MX hosts, and TLS-RPT failure reporting.
The BIMI record at default._bimi: the l= logo (SVG Tiny P/S), the optional a= VMC and the avp= avatar preference – plus the DMARC-enforcement prerequisite.
Every test above is also part of the complete domain security check, which grades your whole domain – website TLS, mail server, DNS, DNSSEC, email authentication and HTTP security headers – in a single run, from A+ to F, with a per-check explanation and remediation tips. Need to publish a record first? Our free Record Studio builds valid SPF, DKIM, DMARC, TLSA and more.