SPF, DKIM and DMARC: what they are and how to check your domain
A free SPF, DKIM and DMARC checker for your domain, no sign-up needed: what the records mean, how to set up DMARC and why your emails end up in spam.
The three records in plain words
Anyone can put any address in the From field. To tell your message from a forgery, the recipient’s mail service checks it against the DNS records of your domain.
A message passes DMARC if it passed SPF or DKIM and the checked domain is the same as in the From field. If there are no records or they contain an error, the message has nothing to prove it came from you — such messages land in spam or are rejected more often.
The records are a requirement, not a guarantee. Mail services also look at the reputation of the server’s address, at complaints from recipients and at the content of the message.
- SPF
- a list of servers allowed to send mail on behalf of the domain. A TXT record on the domain itself, starting with v=spf1
- DKIM
- a signature on the message. The sending server signs every message, and the key to check it sits in DNS under the name selector._domainkey.your-domain
- DMARC
- a rule for the recipient: what to do with a message that failed the check, and where to send reports. A TXT record named _dmarc.your-domain
How to check your domain
The checker reads only public DNS records and the MTA-STS policy file — the same things any mail server sees before delivery.
- Open the “Mail domain check” page: the “Domain check” link is at the bottom of every page of the site. No registration needed.
- Enter a domain or any address on it, for example info@example.com: the part after @ is checked.
- You can leave the DKIM selector field empty — we will try 30 common selectors. If no key is found, open the headers of any message you sent and take the s= value from the DKIM-Signature line.
- Press “Check”. Each record gets a mark — “fine”, “fix”, “error” or “note” — and an explanation of what is wrong.
- Fixed a record but see the same result? The answer is kept for 10 minutes, and DNS changes take time to spread. Check again later.
- For comparison, check alpost.ch — that is what a domain with everything switched on looks like.
What else the check shows
- MX
- the servers that receive the domain’s mail, and their addresses
- MTA-STS
- whether senders must deliver mail to you only over an encrypted channel. We fetch the policy file over HTTPS, the way mail servers do
- TLS-RPT
- whether reports on encryption failures during delivery to you are requested
- DNSSEC
- whether the domain’s zone is signed; the signature is verified by our resolver
- DANE
- whether the keys of your mail servers (TLSA records) are published in a signed zone
- Reverse DNS
- whether the addresses of the MX servers have a reverse name, and whether it points back to the same address
- Blocklists
- we do not query them ourselves: the rules of their free mirrors do not allow it. We give a link to the check at Spamhaus
Common mistakes
- Two SPF records. There must be one: when you add a new mailing service, add its include to the existing record instead of creating a second one.
- More than 10 DNS lookups in SPF. Every include, a and mx needs lookups, and after the tenth the recipient counts an error. The check shows how many you have; remove services you no longer use.
- Ending in +all or ?all — the record forbids nothing. ~all only flags mail from other servers; -all is the strictest.
- A DKIM key shorter than 2048 bits. The check marks it “fix”. A new key is issued by the service that sends your mail.
- A mailing service signs messages with its own domain instead of yours. DKIM passes, but DMARC does not: the signed domain is someone else’s. Look in the service’s settings for a way to connect your own sending domain — that is where they give you a DKIM record for your DNS.
- p=none in DMARC forever. That is monitoring mode: forgeries are still delivered.
- Two DMARC records, or pct below 100. In the first case recipients apply neither; in the second the rule covers only part of the mail.
How to set up DMARC
- List everything that sends mail from your domain: your mail service, newsletters, CRM, online shop. Each must be in SPF or sign messages with DKIM for your domain.
- At your DNS provider, create a TXT record named _dmarc (full name — _dmarc.your-domain) with the value v=DMARC1; p=none; rua=mailto:address-for-reports.
- Read the reports for a week or two: they show which servers send mail in your name and whether it passes the check.
- When all your servers pass, change p=none to p=quarantine — failing messages will go to spam. Later move to p=reject: such messages will be rejected.
DMARC reports in your account
Reports are sent by recipients’ mail services as archives with XML, which are awkward to read by hand. If you have an Alpost mailbox, point the reports to us: your account will show a summary.
- Open your account, the “Monitoring” section, the “Mail reports for your domain” card. Enter the domain and press “Connect”.
- Confirm that the domain is yours: add a TXT record named _alpost.your-domain to its DNS, with the value alpost-verify=… that your account shows. Then press “Check the record”. DNS changes sometimes take up to an hour.
- Add rua=mailto:reports@alpost.ch to the domain’s DMARC record. If there is already a report address, add ours after a comma: rua=mailto:your-address,mailto:reports@alpost.ch. If there is no DMARC record, your account shows a ready one.
- Reports usually arrive once a day, and only for days when the service received mail from your domain. We process them every hour.
- The summary covers the last 30 days: how many messages, how many passed DMARC, how many sending servers there were, and up to ten servers with the most messages.
- Up to three domains per mailbox. A domain can be confirmed by only one mailbox; Alpost domains cannot be connected.
- Reports contain only server addresses, message counts and check results — no message text and no recipients. Disconnect a domain and its reports are deleted within an hour.
What is not here
- Alpost gives no mailboxes on your own domain: addresses are issued only on our five domains. The check and the reports are for a domain whose mail is handled by another service.
- You cannot send mail as your own domain through our server: it accepts for sending only mail from the address you signed in with. On the hosting, the mail() function is disabled.
- We do not set up your domain’s records: you add SPF, DKIM and DMARC at your DNS provider, and the DKIM key comes from the service that sends your mail.
- If you handed the domain to us entirely for a website, there is no DNS record editor in your account — you cannot add the TXT record for confirmation or a DMARC record.
- No analysis of a single message: the check reads DNS records, not how a particular message fared. That is shown in the Authentication-Results header at the recipient’s end.