Big protection. Even on the free plan. Meet your new DNS home
KumoDNS
Free tool

Mail check.

SPF, DKIM, DMARC and MX for any domain — including the SPF lookup count that quietly breaks email once it passes ten.

10 of 10 checks left this hour. (Psst — need more? Sign in now)

The one that breaks quietly

Three of these four records fail loudly enough that somebody notices. The SPF lookup limit does not. A record may cost ten DNS lookups to evaluate, counting every include inside every other include — and one of those belongs to a company whose DNS you do not control.

So a record that worked for years stops working on a day you changed nothing, receiving servers start treating your domain as having no SPF at all, and there is no error anywhere to tell you. That is the number this page counts for you.

What is the SPF lookup limit, and why does it matter?

An SPF record may cost at most ten DNS lookups to evaluate, counting every include, a, mx, ptr and exists — including the ones inside records you include from other companies. Go over and receiving servers return a permanent error, and most then treat your domain as having no SPF at all. Nothing warns you, and it often breaks because a provider you include added to their own record.

Why does it say it cannot prove there is no DKIM?

A DKIM key lives at a name only its owner knows, and DNS gives no way to list which of those names exist. We try the common ones. If your provider uses a selector we did not guess, your DKIM is fine and this check simply cannot see it. Any tool that tells you otherwise is guessing too, and hiding it.

My DMARC says p=none. Is that a problem?

It is the right place to start and the wrong place to stay. p=none asks receivers to do nothing, so it protects nothing on its own — it exists so you can collect reports and see who sends as your domain before you turn the policy up. A domain left at p=none for years has DMARC in name only.

Do I need all four records?

MX only if you receive mail. SPF and DMARC on every domain you send from, and on ones you never send from too — that is what stops somebody forging them. DKIM comes from whoever sends your mail, and they will tell you what to publish.

Fix it where you host the zone

Every change published to our nameservers in seconds, with a full history of what changed and a recycle bin for the days it goes wrong. Every zone is DDoS-protected, on every plan including the free one.

Top