Skip to content
toolsdocks

Review email authentication records

Enter your domain and, if you know them, your DKIM selectors. The page reads the published TXT records through DNS over HTTPS and lists problems record by record.

Uses a public service
Loading tool…

How to use

  1. Enter your domain.
  2. Add DKIM selectors if you know them (common ones are tried automatically).
  3. Fix the issues listed for each record.

Worked example

v=spf1 include:_spf.example.net ~all with 12 nested lookups is flagged: SPF allows at most 10 DNS lookups.

Supported formats and limits

InputDomain, optional DKIM selectors
OutputValidation report
EngineDNS-over-HTTPS TXT lookups from your browser with SPF include/redirect expansion and DMARC tag parsing

Limitations

  • Valid records do not guarantee delivery; mailbox providers also use reputation and content.

Questions

Does a clean result mean my email will be delivered?

No. The checker reads the records published in DNS and checks their syntax and limits. It does not send a test message or see how a mailbox provider judges your mail, which also depends on reputation and content.

Why was my DKIM record not found?

DKIM keys live under a selector name that the sending service chooses. The tool tries the selectors you enter plus a list of common ones; if your provider uses a different name, add it from a message header (the s= value in DKIM-Signature).

What does the SPF lookup count mean?

SPF allows at most 10 DNS lookups from include, a, mx, ptr, exists and redirect. The tool follows includes and redirects, counts them, and flags records that go over, loop, or point to names without SPF.

Guides

Privacy

Uses a public service. Your browser sends only what is listed below (for example a domain name) to the named public service. No files or other content are sent.

See the privacy policy for how toolsdocks handles data.