Free tools
Find out what your domain is actually publishing
Every tool here reads public DNS, shows you the raw record, and explains what it means. No account, no email address, and no result held back behind a signup.
Domain Trust Scanner
Start hereThirty checks across DNS, email authentication and mail transport, with a score you can reproduce.
“Is my domain set up to be trusted — and what should I fix first?”
Check my domainCan someone else send mail as my domain?
SPF Inspector · DKIM Inspector · DMARC Inspector
Is mail to my domain encrypted in transit?
MTA-STS Checker
Can a resolver tell my answers from forged ones?
DNSSEC Analyzer
Why is my logo not showing in the inbox?
BIMI Checker
DNS
Whether the zone itself is served correctly, and whether resolvers can tell your answers from forged ones.
Email authentication
Who is allowed to send mail as your domain, and what happens to anyone who is not.
SPF Inspector
Expand a domain's SPF record, walk every include, and count it against the 10-lookup limit.
“Will my SPF record pass, or has it quietly gone over the lookup limit?”
Run itDMARC Inspector
Fetch a domain's DMARC record, explain every tag, and say whether it actually stops spoofing.
“Can someone send mail as my domain right now?”
Run itDKIM Inspector
Find a domain's DKIM keys, and check their length, test-mode flag and revocation state.
“Is my DKIM key actually published, and is it strong enough?”
Run itMail transport and identity
How mail reaches you, whether it is encrypted in transit, and whether your brand is visible when it arrives.
MTA-STS Checker
Read the _mta-sts record, fetch the live policy file, and check TLS-RPT alongside it.
“Is mail to my domain required to travel over TLS, or is a downgrade still possible?”
Run itBIMI Checker
Look up the BIMI record, preview the logo, and validate it against the SVG profile Gmail expects.
“Why is my logo not showing up next to my mail?”
Run itWhat these tools can and cannot tell you
Every check reads what is published in public DNS, plus — for MTA-STS and BIMI — the public HTTPS resource the record points at. That is enough to catch the large majority of real misconfigurations, because most of them are visible from outside.
It is not enough to tell you whether your mail is actually being delivered. A domain can publish a flawless SPF, DKIM and DMARC set and still have a sending service that is not aligned, or a forwarding path that breaks alignment after the fact. Only aggregate DMARC reports show you that, because only the receiving mailbox providers can see it.
We also cannot enumerate your DKIM selectors. DNS has no way to list what exists under a name, so any DKIM check — ours or anyone else's — is either guessing from a list of common selectors or being told which one to look at. The DKIM Inspector lets you supply yours, and says which results came from a guess.
Found something you want fixed for good?
Every tool links to the manual fix first. If you would rather not maintain it by hand, that is what the products are for — and the prices are published.