SPF & DMARC Checker
Check whether your domain name is protected against email spoofing: reads the SPF and DMARC records, explains them in plain language and gives the records to publish.
This tool needs the internet
The domain name you enter is sent to Cloudflare's public DNS resolver (cloudflare-dns.com), or to Google's (dns.google) if it does not answer, to read its public DNS records. Nothing is sent to Youtilz servers.Learn more
SPF
SPF lists the servers allowed to send emails for your domain.
DMARC
DMARC tells mailbox providers what to do with an email that claims to come from your domain but passes neither the SPF nor the DKIM check.
TXT records to publish
SPF, on the domain itself
DMARC, on the _dmarc name of the domain
DKIM, the third pillar, signs your emails. It cannot be checked here without knowing the "selector" chosen by your email provider: see its documentation.
Is Your Domain Protected Against Email Spoofing?
By default, anyone can send an email that shows your address as the sender. This is the basis of the fake invoices and fake bank detail changes that target businesses and their customers.
The SPF and DMARC checker reads the public DNS records of your domain and tells you, in plain language, whether they prevent this spoofing. When something is missing, it suggests the records to publish.
How to Use
- Enter your domain name, or simply your email address (
contact@example.com) - Click "Check"
- Read the verdict, then the details of the SPF and DMARC records
- If needed, copy the suggested records and send them to the person who manages your DNS
SPF, DKIM and DMARC in Brief
SPF
A TXT record that lists the servers allowed to send emails for your domain: your email service, your newsletter tool, your invoicing software…
DKIM
A signature added to each email by the sending server, which can be verified with a key published in your DNS.
DMARC
The rule that says what to do with an email that fails both SPF and DKIM: do nothing (none), send it to spam (quarantine) or reject it (reject).
SPF alone is not enough: it checks the technical sending address, not the one the recipient sees. It is DMARC that links the two and causes spoofed emails to be set aside.
Setting Up DMARC Without Blocking Your Emails
- List everything that sends emails on your behalf: email service, website, newsletter, invoicing, CRM.
- Declare them in SPF and enable DKIM with each of them.
- Publish DMARC with
p=noneand aruaaddress: you receive reports without blocking anything. - After a few weeks, when the reports no longer show legitimate emails failing, switch to
p=quarantine. - Finish with
p=reject.
A domain that never sends emails (a secondary domain, for example) can be locked right away with v=spf1 -all and v=DMARC1; p=reject;.
Why It Has Become Essential
Since February 2024, Gmail and Yahoo have required SPF or DKIM from all senders, and SPF, DKIM and DMARC from bulk senders (for Gmail, more than 5,000 emails a day). Without these records, your legitimate emails are more likely to end up in spam.
Above all, a domain without an enforced DMARC policy can be used to deceive your customers and suppliers, who trust your address.
Limitations
- DKIM is not checked: its key is published under a name (the selector) that is specific to each provider and cannot be reliably guessed.
- The tool reads the published records; it does not send any test email.
- When counting SPF DNS lookups, the tool follows includes, up to a limit of 20 queries.
- For a subdomain without its own DMARC record, the tool looks for the record of its parent domains, whose policy also applies to subdomains.