Skip to content

Email security

Email security checker

Check the DNS records that decide whether mail forged in a domain's name is delivered: SPF, DKIM and DMARC, and for a domain that sends no mail, the records that say so. Nothing is sent: the check reads public DNS only.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

The records work together. SPF lists the servers allowed to send for the domain, DKIM publishes the keys that verify signatures on its mail, and DMARC tells receivers what to do with mail that fails both SPF and DKIM alignment with the From address, and where to send reports about it.

Each check passes, raises a finding or does not apply: a domain without MX records is not expected to publish SPF, and DKIM is looked for only where the domain sends mail or you name a selector. A finding names one thing to change and how serious it is. DKIM that could not be confirmed is informational, because selectors cannot be listed from DNS.

Typical findings are a DMARC policy still at p=none, an SPF record pushed past 10 lookups as sending services were added, and a domain that sends no mail but does not say so, which leaves it open to spoofing.

How to fix common issues

No SPF record

Publish a TXT record starting v=spf1 that lists the services that send your mail and ends in -all or ~all, for example v=spf1 include:_spf.google.com -all.

More in the SPF check reference

More than one SPF record

Merge the records into a single v=spf1 TXT record.

More in the SPF check reference

SPF does not reject unlisted senders

End the record with -all (or ~all while testing) after listing your real sending services.

More in the SPF check reference

SPF needs too many DNS lookups

Remove unused includes, replace a/mx/ptr mechanisms with IP ranges where stable, or use your provider's flattened include.

More in the SPF check reference

SPF record has errors

Correct the record. Each term must be a valid mechanism (ip4:, ip6:, include:, a, mx, exists:) or modifier (redirect=, exp=).

More in the SPF check reference

No DMARC policy

Publish a TXT record at _dmarc.example.com such as v=DMARC1; p=none; rua=mailto:dmarc@example.com, review the reports, then move to p=quarantine and p=reject.

More in the DMARC check reference

DMARC is in monitoring mode

Once reports show your legitimate mail passing, move to p=quarantine and then p=reject.

More in the DMARC check reference

DMARC applies to only part of the mail

Remove the pct tag (it defaults to 100) once you are confident in the policy.

More in the DMARC check reference

DMARC reports are not requested

Add rua=mailto: with an address or a DMARC reporting service.

More in the DMARC check reference

DMARC record has errors

Correct the record. It must start with v=DMARC1; followed by a p= tag (none, quarantine or reject).

More in the DMARC check reference

DKIM could not be confirmed

Confirm in your mail service (Google Workspace, Microsoft 365 and others) that DKIM signing is turned on for the domain.

More in the DKIM check reference

Domain without mail is not protected from spoofing

Publish v=spf1 -all, a DMARC record v=DMARC1; p=reject;, and optionally a null MX (0 .).

More in the Non-sending domain protection check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 names SPF, DKIM or DMARC. Together they are technical evidence for broader controls: secure configuration of internet-facing services, and protecting information sent by email (ISO/IEC 27001:2022 Annex A 5.14, information transfer). Where mail runs on a cloud service such as Google Workspace or Microsoft 365, they are also part of setting that service up securely (5.23, information security for use of cloud services).

The organisation still has to establish who owns the domain's mail records, how a new sending service is approved and added, how DMARC reports are reviewed, and how domains that send no mail are kept protected. The records show the settings at one moment, not the process that keeps them right.

Scope and limitations

Related guides

Questions

What is the difference between SPF, DKIM and DMARC?
SPF lists the servers allowed to send mail for a domain. DKIM signs each message so a receiver can check it was not altered and who signed it. DMARC tells receivers what to do when mail fails both in a way that matches the From address, and sends the domain owner reports.
Does a domain that sends no email need SPF and DMARC?
Yes. Unused domains are still used for spoofing. Publish v=spf1 -all and a DMARC policy of p=reject so receivers refuse mail claiming to come from them; a null MX record also says the domain accepts no mail.
Do I need all three?
DMARC depends on the other two: it passes when SPF or DKIM passes and aligns with the From domain. SPF alone fails when mail is forwarded, and DKIM alone gives receivers no policy to act on, so set up all three.

Related security tools