Email security
Email security checker
Check the DNS records that decide whether mail forged in a domain's name is delivered: SPF, DKIM and DMARC, and for a domain that sends no mail, the records that say so. Nothing is sent: the check reads public DNS only.
What this checks
- MX records: whether the domain receives mail, or publishes a null MX (
0 ., RFC 7505) to say it accepts none. - SPF: exactly one valid
v=spf1record, not ending in+allor?all, that needs no more than 10 DNS lookups. - DMARC: one valid record at
_dmarc.<domain>(or at the organisational domain, for a subdomain without one), its policy, how much mail it covers and whether aggregate reports are requested. - DKIM: keys at up to three selectors you enter and at 13 common selectors, for a domain that sends mail or when you name a selector.
- Non-sending domains: a domain with no MX records, and no SPF record that authorises senders, should publish
v=spf1 -alland a DMARC policy ofp=reject.
What the result means
The records work together. SPF lists the servers allowed to send for the domain, DKIM publishes the keys that verify signatures on its mail, and DMARC tells receivers what to do with mail that fails both SPF and DKIM alignment with the From address, and where to send reports about it.
Each check passes, raises a finding or does not apply: a domain without MX records is not expected to publish SPF, and DKIM is looked for only where the domain sends mail or you name a selector. A finding names one thing to change and how serious it is. DKIM that could not be confirmed is informational, because selectors cannot be listed from DNS.
Typical findings are a DMARC policy still at p=none, an SPF record pushed past 10 lookups as sending services were added, and a domain that sends no mail but does not say so, which leaves it open to spoofing.
How to fix common issues
No SPF record
Publish a TXT record starting v=spf1 that lists the services that send your mail and ends in -all or ~all, for example v=spf1 include:_spf.google.com -all.
More than one SPF record
Merge the records into a single v=spf1 TXT record.
SPF does not reject unlisted senders
End the record with -all (or ~all while testing) after listing your real sending services.
SPF needs too many DNS lookups
Remove unused includes, replace a/mx/ptr mechanisms with IP ranges where stable, or use your provider's flattened include.
SPF record has errors
Correct the record. Each term must be a valid mechanism (ip4:, ip6:, include:, a, mx, exists:) or modifier (redirect=, exp=).
No DMARC policy
Publish a TXT record at _dmarc.example.com such as v=DMARC1; p=none; rua=mailto:dmarc@example.com, review the reports, then move to p=quarantine and p=reject.
DMARC is in monitoring mode
Once reports show your legitimate mail passing, move to p=quarantine and then p=reject.
DMARC applies to only part of the mail
Remove the pct tag (it defaults to 100) once you are confident in the policy.
DMARC reports are not requested
Add rua=mailto: with an address or a DMARC reporting service.
DMARC record has errors
Correct the record. It must start with v=DMARC1; followed by a p= tag (none, quarantine or reject).
DKIM could not be confirmed
Confirm in your mail service (Google Workspace, Microsoft 365 and others) that DKIM signing is turned on for the domain.
Domain without mail is not protected from spoofing
Publish v=spf1 -all, a DMARC record v=DMARC1; p=reject;, and optionally a null MX (0 .).
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 names SPF, DKIM or DMARC. Together they are technical evidence for broader controls: secure configuration of internet-facing services, and protecting information sent by email (ISO/IEC 27001:2022 Annex A 5.14, information transfer). Where mail runs on a cloud service such as Google Workspace or Microsoft 365, they are also part of setting that service up securely (5.23, information security for use of cloud services).
The organisation still has to establish who owns the domain's mail records, how a new sending service is approved and added, how DMARC reports are reviewed, and how domains that send no mail are kept protected. The records show the settings at one moment, not the process that keeps them right.
Scope and limitations
- The check reads public DNS through public resolvers. No mail is sent and no mail server is contacted, so it does not test delivery or how a particular receiver applies your records.
- DKIM keys can only be found at the selectors the check tries, so DKIM that could not be confirmed is not a finding of a problem.
- It checks the domain entered only. SPF is not inherited by subdomains, so each name that sends mail, and each other domain you own, needs its own check.
- It does not look at MTA-STS, TLS reporting (TLS-RPT), BIMI or the mail servers' own configuration.
Related guides
Questions
- What is the difference between SPF, DKIM and DMARC?
- SPF lists the servers allowed to send mail for a domain. DKIM signs each message so a receiver can check it was not altered and who signed it. DMARC tells receivers what to do when mail fails both in a way that matches the From address, and sends the domain owner reports.
- Does a domain that sends no email need SPF and DMARC?
- Yes. Unused domains are still used for spoofing. Publish v=spf1 -all and a DMARC policy of p=reject so receivers refuse mail claiming to come from them; a null MX record also says the domain accepts no mail.
- Do I need all three?
- DMARC depends on the other two: it passes when SPF or DKIM passes and aligns with the From domain. SPF alone fails when mail is forwarded, and DKIM alone gives receivers no policy to act on, so set up all three.
Related security tools
- DMARC checker - Look up a domain's DMARC record, read its policy and reporting, and see what to change.
- SPF checker - Check a domain's SPF record, its all mechanism and how many of the 10 DNS lookups it uses.
- DKIM checker - Look up a DKIM key at your selector or at common ones, with its key type and size.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

