Check your domain's public DNS TXT records for SPF, DKIM and DMARC to improve email deliverability and prevent spoofing. This verifies mail-related DNS only — it does not issue an SSL/TLS certificate.
Checks your domain's public DNS TXT records for email authentication. This does not issue an SSL/TLS certificate; it only verifies mail-related DNS.
@ in your addresses.Without these records, mailbox providers can't tell your real mail from a spoofed message pretending to be you. The result is twofold: your legitimate email lands in spam, and attackers can impersonate your domain in phishing. Since 2024, Gmail and Yahoo require SPF, DKIM and DMARC for bulk senders — so missing records increasingly mean undelivered mail, not just weaker security.
p=none forever. You get reports but never enforce, so spoofing still gets through.Email authentication secures who can send as your domain. To sign and encrypt the content of individual messages, you need an S/MIME certificate — a separate, complementary layer.
No. It only queries your domain's public DNS TXT records — the same information any mail server can already see. No mailbox access, no credentials.
No. SPF/DKIM/DMARC are DNS records that authenticate your mail. An SSL/TLS certificate secures your website. This tool checks the former and issues nothing.
Yes, for reliable delivery. SPF and DKIM prove authenticity two different ways; DMARC enforces them and gives you reporting. Gmail and Yahoo now expect all three from bulk senders.
These records authenticate your domain's mail servers. S/MIME signs and encrypts individual messages with a certificate. They solve different problems and work well together.