DMARC explained (RFC 9989)
The full reference on the current standard: every tag with its real default, the DNS tree walk worked through, ten annotated example records, the rollout plan, how to read the reports & a troubleshooting tree.
Want to focus on one area? Each of these free tests goes deep on a single topic, with the checks explained and the sources named — or run the full domain security check to cover everything in one pass. Eight of these pages explain one topic each and hand you straight to the scan that measures it — the DMARC page is a reference rather than a test, and the DNS lookup queries live on its own page. Everything here reads live data, and none of it needs an account.
The full reference on the current standard: every tag with its real default, the DNS tree walk worked through, ten annotated example records, the rollout plan, how to read the reports & a troubleshooting tree.
Drop or paste the aggregate reports receivers send to your rua address: every sending source with its DMARC, DKIM and SPF results, a red/orange/green light, override reasons and every RFC 9990 field explained – read in your browser, nothing uploaded.
Email authentication: SPF syntax and the 10-lookup limit, DKIM selectors and key length, the DMARC policy and reporting – plus BIMI, MTA-STS and TLS-RPT.
TLSA records (3 1 1), the DNSSEC prerequisite and whether the published TLSA data matches the certificate your MX hosts actually serve.
Zone signing, the DS record at the registrar, recommended algorithms (RFC 9904), signature lifetimes, NSEC3 and automatic DS maintenance.
HSTS, Content-Security-Policy quality, clickjacking protection, cookie flags and CORS – plus what the module checks beyond the classic headers.
The website's HTTPS: certificate chain & trust, validity and hostname, key strength, TLS versions (1.0–1.3), cipher suites & forward secrecy, HSTS and the HTTP→HTTPS redirect.
The _mta-sts record and the HTTPS policy file, its mode and max_age, whether the mx list matches your real MX hosts, and TLS-RPT failure reporting.
The BIMI record at default._bimi: the l= logo (SVG Tiny P/S), the optional a= VMC and the avp= avatar preference – plus the DMARC-enforcement prerequisite.
Compare the answers of 11 public resolvers, and the zone's own name servers alongside them: propagation, DNSSEC status, blocklists.
If you arrived with a symptom rather than a protocol name, start here. The right-hand column is the page that explains the mechanism behind the symptom and shows you what a correct configuration looks like.
| What you are seeing | Start here |
|---|---|
| Your mail is landing in recipients' spam folders | SPF, DKIM & DMARC check |
| Someone is sending mail that looks like it comes from your domain | DMARC explained (RFC 9989) |
| You published DMARC and legitimate mail started being rejected | DMARC explained (RFC 9989) |
| You receive DMARC reports as XML attachments and cannot make sense of them | DMARC report viewer |
| Your brand logo does not show up in the inbox | BIMI check |
| Mail sent to you should be encrypted in transit, and you want it enforced | MTA-STS test |
| You want the certificate of your mail servers pinned in DNS | DANE mailserver test |
| Browsers warn visitors about your certificate, or the grade is poor | SSL/TLS certificate test |
| A header scanner gave your site a bad score | Security headers test |
| You want your zone cryptographically signed, or the chain is broken | DNSSEC test |
| A DNS change is not taking effect, or resolvers disagree | DNS lookup & propagation |
Eight of the topics above are graded by the complete domain security check, which covers your whole domain — website TLS, mail server, DNS, DNSSEC, email authentication and HTTP security headers — in a single run, from A+ to F, with a per-check explanation and remediation tips. One page stands apart on purpose: the DNS lookup adds an ungraded comparison across 11 public resolvers and 7 blocklist resolvers that the full scan does not run — the zone's own name servers are checked in both. Otherwise the topic pages and the full scan use the same engine, so a finding you see on one you will see on the other.
Nearly every check is documented: what it looks at, how it is scored, what weight it carries and how to fix a failure. The reference is split by module — website TLS, mail server TLS & DANE, email authentication, DNS, DNSSEC and HTTP security headers — with the rating caps and the scoring model explained on the checks & scoring page.
Testing tells you what is wrong; the Record Studio writes the record that fixes it — SPF, DKIM, DMARC, BIMI, TLSA, SMIMEA, MTA-STS, TLS-RPT, CAA, security.txt and Null MX, all generated in your browser. For a message you actually send or receive, the live email test goes further than DNS can: it measures a real message end to end.