Email security check.
Check a domain's SPF, DMARC, MTA-STS, TLS-RPT, BIMI and DKIM records, with a plain-English verdict and the records to add.
What it checks
Checks
SPF: one record, its all mechanism, and the DNS lookups it needs with every include followed (the limit is ten).
DMARC: the policy, the subdomain policy, the percentage, and where reports go.
MTA-STS: the DNS record, and the policy file at mta-sts.<domain> (one HTTPS request).
TLS-RPT and BIMI records.
DKIM keys for the selectors you name: present, revoked, and roughly how long.
Doesn’t check
Whether your mail actually passes. That depends on each message and the server that sends it.
DKIM selectors you do not name. DNS has no way to list them.
Blocklists, your mail servers' TLS, or deliverability.
Questions
Which DKIM selector should I enter?
Your email provider sets it: Google Workspace uses google, Microsoft 365 uses selector1 and selector2. In any message you sent, the DKIM-Signature header names it as s=.
Which DMARC policy should I have?
Start at p=none with a rua address, to see who sends mail as your domain. Once the reports show only your own services, move to p=quarantine, then p=reject.
Is ~all or -all better for SPF?
Both stop spoofing once DMARC is enforced. -all fails unlisted servers outright; ~all marks them suspicious and leaves the decision to DMARC, which is the more common setting.
Does this send any email?
No. It reads DNS records through 1.1.1.1, and fetches one file, the MTA-STS policy, when the domain publishes one.
Is what I enter stored?
No. Your IP address is used only to count requests for rate limiting, for one minute, and what you enter is not logged or kept.