Email DNS Check Tool

Verify your complete email DNS stack (MX, SPF, DMARC, and DKIM) instantly to troubleshoot delivery and spam issues.

How to troubleshoot email delivery and spam issues

If your emails are bouncing or landing in the spam folder of Gmail or Outlook, your email DNS configuration is likely incomplete. Enter your domain above to run a comprehensive check on the four pillars of email routing and authentication.

Interpreting your Email DNS results

  • MX (Mail Exchange): Ensure your domain has valid MX records with correct priorities. If this is missing, you cannot receive emails.
  • SPF (Sender Policy Framework): Check if your SPF record exists and strictly contains the IPs/services allowed to send emails on your behalf. Warning: Having multiple SPF records will cause instant failures.
  • DKIM (DomainKeys Identified Mail): If you entered a selector, verify that the cryptographic key is correctly published. Broken DKIM keys will break email signatures.
  • DMARC (Domain-based Message Authentication): Ensure you have a DMARC policy (p=none, quarantine, or reject) published at the _dmarc subdomain to tell receivers how to handle unauthenticated mail.

Email DNS check: MX, SPF, DMARC, DKIM

Email DNS configuration is a common source of delivery problems. This use case combines MX, SPF, DMARC, and DKIM checks so you can verify all critical records in one place. A valid MX ensures mail delivery, SPF defines sending policy, DMARC enforces alignment, and DKIM provides cryptographic signatures. Checking them together reduces the chance of a partially configured setup.

A typical failure pattern is that MX is correct but SPF is missing or too permissive, or DMARC is published at the wrong hostname. DKIM failures often come from using the wrong selector or publishing the key at the wrong subdomain. Use this checklist approach to validate the entire email stack before sending large campaigns or onboarding a new provider.

If you need related checks, try DKIM check DNS lookup and Email deliverability score DNS lookup.

Start with MX to ensure delivery, then SPF to authorize senders, then DKIM for signing, and finally DMARC for enforcement and reporting.

SPF can fail if you have multiple SPF records or too many DNS lookups from include mechanisms. Keep it to a single record and under lookup limits.

DMARC must be published as a TXT record at _dmarc.yourdomain. Publishing it at the apex will not work.

It is a label that identifies which DKIM key to use. The DNS record is published at selector._domainkey.domain.

DMARC alignment requires that the visible From domain aligns with SPF or DKIM domains. Check your mail provider settings and DNS records together.

DNS changes follow TTLs, so allow for caching. During setup, use lower TTLs to speed up validation.