Free tool · No signup

SPF, DKIM & DMARC checker, free and instant.

Enter the domain you send cold email from. In a few seconds you will know whether Gmail, Outlook and Yahoo can verify it, and get the exact record to publish for anything missing.

Free, no signup. We read public DNS records and store nothing about your domain.

What the checker looks at.

Four DNS records decide whether a receiving server believes an email really came from your domain. The checker reads all four from public DNS and grades each one.

  • MX tells the world where mail for your domain is delivered. Without it nobody can reply, and filters distrust a domain that cannot receive. We also use it to work out your mail provider, so the next three checks look for the right things.
  • SPF is a TXT record at the root of the domain that lists the servers allowed to send as you. We check that exactly one exists, that it includes your provider (for Google Workspace that is _spf.google.com), and that it ends in ~all or -all.
  • DKIM is a public key your mail provider signs every message with. It lives at a name like google._domainkey.yourdomain.com. We try your provider's selector first and then the common ones, or the selector you enter.
  • DMARC is a TXT record at _dmarc.yourdomain.com that tells receivers what to do when SPF and DKIM fail, and where to send reports. We read the policy: none only reports, quarantine and reject protect.

These are the same checks FoxReach runs on every inbox you connect, so the free tool and the app give you the same verdict.

Why it matters for cold email.

Since February 2024 Gmail and Yahoo require bulk senders to authenticate with SPF and DKIM and to publish a DMARC record, and they reject or junk mail that does not. Microsoft set the same bar for high-volume senders to Outlook.com in 2025. Cold email is judged more strictly than newsletters, because it goes to people who never signed up.

Authentication will not get a bad email into the inbox, but missing authentication will keep a good one out. It is the first thing to fix, it is free, and it takes ten minutes in your DNS settings. After that, inbox placement comes down to warming up new inboxes, sending volume, and the email itself (our email spam checker covers that part).

One more rule worth following: send cold email from a separate domain, not the one your company runs on. If a campaign hurts that domain's reputation, your invoices and support replies keep landing. Every new domain needs these four records before its first send.

Reading your result.

Pass means the record exists and does its job. Weak means it exists but leaves a gap, like an SPF record that does not include your provider or a DMARC policy of p=none. Missing means receivers cannot verify that part at all. No answer means DNS timed out, which is not a verdict; check again in a minute.

For anything that is not a pass, the result shows the record to publish: the type, the host to enter in your DNS provider, and a value you can copy. Most DNS providers use @ for the root of the domain and want only the first part of a name (_dmarc, not _dmarc.yourdomain.com).

If DKIM shows missing but you know you set it up, your provider may use a selector we do not guess. Open an email you sent, view the original, and find s= in the DKIM-Signature header. Enter that selector and check again. DNS changes usually show up within an hour, though some providers take up to a day.

Questions,
answered.

They are three DNS records that let a receiving mail server check an email really came from your domain. SPF lists the servers allowed to send as you, DKIM is a public key that verifies a signature on every message, and DMARC tells receivers what to do when those checks fail and where to send reports.

Yes. Gmail and Yahoo have required SPF, DKIM and a DMARC record from bulk senders since February 2024, and Microsoft set the same rule for high-volume senders to Outlook.com in 2025. Cold email is judged more strictly than newsletters, so treat all three as required on every domain you send from.

DKIM keys live under a selector name that varies by provider, and DNS has no way to list them. We try your provider's selector and the common ones. If yours is different, open an email you sent, view the original message, find s= in the DKIM-Signature header, and enter that selector in the checker.

Start with p=none and a rua address you read, so nothing is blocked while you confirm SPF and DKIM pass for all your real mail. After a week or two of clean reports, move to p=quarantine. p=reject is the strongest setting and fine once you are sure every service that sends as you is authenticated.

Usually minutes to an hour. Some DNS providers and long TTL values can stretch it to a day. If the checker still shows the old value, wait and check again; there is nothing to clear on our side because every check reads live DNS.

Better not. Use a separate domain that looks like your brand (for example getacme.com for acme.com) so a campaign can never hurt the reputation of the domain your team, invoices and support run on. The new domain needs its own MX, SPF, DKIM and DMARC records before the first send.

No. The checker reads public DNS records and returns the result. Nothing about the domain is saved, and you do not need an account.

Authenticated domain,
now send from it.

FoxReach checks SPF, DKIM and DMARC on every inbox you connect, warms each one up, and sends your campaigns from them.