SPF, DKIM, DMARC and MX for any domain — including the SPF lookup count that quietly breaks email once it passes ten.
Three of these four records fail loudly enough that somebody notices. The SPF lookup limit does not. A record may cost ten DNS lookups to evaluate, counting every include inside every other include — and one of those belongs to a company whose DNS you do not control.
So a record that worked for years stops working on a day you changed nothing, receiving servers start treating your domain as having no SPF at all, and there is no error anywhere to tell you. That is the number this page counts for you.
An SPF record may cost at most ten DNS lookups to evaluate, counting every include, a, mx, ptr and exists — including the ones inside records you include from other companies. Go over and receiving servers return a permanent error, and most then treat your domain as having no SPF at all. Nothing warns you, and it often breaks because a provider you include added to their own record.
A DKIM key lives at a name only its owner knows, and DNS gives no way to list which of those names exist. We try the common ones. If your provider uses a selector we did not guess, your DKIM is fine and this check simply cannot see it. Any tool that tells you otherwise is guessing too, and hiding it.
It is the right place to start and the wrong place to stay. p=none asks receivers to do nothing, so it protects nothing on its own — it exists so you can collect reports and see who sends as your domain before you turn the policy up. A domain left at p=none for years has DMARC in name only.
MX only if you receive mail. SPF and DMARC on every domain you send from, and on ones you never send from too — that is what stops somebody forging them. DKIM comes from whoever sends your mail, and they will tell you what to publish.
Every change published to our nameservers in seconds, with a full history of what changed and a recycle bin for the days it goes wrong. Every zone is DDoS-protected, on every plan including the free one.