Check your SPF, DKIM and DMARC records: a free paste-in checker
Why your email lands in spam, read off your own DNS records. Nothing you paste leaves this page.
To check your email records, copy the three TXT records from your domain's DNS and paste them below. This page reads them in your browser, explains each part in plain words, and flags the mistakes that send your mail to spam or let other people send email as you.
SPF lists the servers allowed to send email for your domain. DKIM is a signature on each message, checked against a public key in your DNS. DMARC tells receivers what to do when both of those fail, and where to send reports. Gmail asks every sender for SPF or DKIM, and anyone sending 5,000 or more messages a day for all three.
Step 1: look up your records
The links open Google's free DNS lookup in a new tab. That sends your domain name to Google, not to this page. If you'd rather not, run the commands in a terminal; on Windows, use nslookup -type=TXT with the same names.
Finding your DKIM selector: open an email you sent, choose "Show original" (Gmail) or "View message source", and find the DKIM-Signature header. The selector is the value after s=. Google Workspace uses google unless you changed it. Microsoft 365 uses selector1 and selector2. Each service that sends for you (a newsletter tool, a shop, a booking system) has its own.
Step 2: paste them here
Paste the whole answer, quotes and all. If the lookup shows several TXT records for your domain, paste them all: the checker finds the SPF one.
The usual fixes, in order
- One SPF record, not two. Each new email service tells you to "add a TXT record". Add its
include:to your existing SPF line instead. Twov=spf1records make SPF fail for everything. - Turn on DKIM in each service that sends for you. Most give you a record to add (often a CNAME), then a button to start signing. Adding the record alone doesn't sign anything.
- Start DMARC at
p=nonewith a report address. Read the reports for two to four weeks. They list every server sending as your domain, including the ones you forgot. - Then tighten it. When all your real mail passes, move to
p=quarantine, thenp=reject. This is the step that stops other people sending email as you.
DNS changes can take from a few minutes to a day to show up, depending on the record's TTL. Look the record up again before you decide a change didn't work.
What this can't tell you
- Whether the records are really published. It reads what you paste. The lookup links above show what the world sees.
- The full SPF lookup count. It counts the lookups in your own record; each
include:adds its own, and you'd look those up one by one. - Alignment. DMARC passes only when the domain SPF or DKIM checked matches the domain in the visible From: address. That needs a real message: send one to a Gmail address, choose "Show original", and read the SPF, DKIM and DMARC lines at the top.
Sources: Gmail's email sender guidelines, RFC 7208 (SPF), RFC 6376 (DKIM), RFC 8301 (DKIM key sizes), and RFC 9989, the DMARC update published in May 2026, which replaced RFC 7489 and removed the pct, rf and ri tags.
You check your own records instead of waiting for a customer to say your email went to spam. I write step-by-step guides for people who look after their own website and email: they're on the blog.
Made by taktekbot. Free and open source: github.com/taktekbot/spf-dkim-dmarc-check