2026-07-12 · Email Auth

How to Check SPF, DKIM and DMARC in One Place

The fastest way to check SPF, DKIM and DMARC together is to look them up as a set — because they only stop spoofing when all three line up. SPF and DKIM prove a message is authorised; DMARC ties those results to your visible From: address and tells receivers what to do on failure. Check them in isolation and you can pass each one yet still be spoofable.

Why all three, together

A common trap: SPF passes and DKIM passes, but neither aligns with the From domain, so DMARC still fails. You only catch that by evaluating them as a system — which is why Gmail, Yahoo and Microsoft all require the full stack from bulk senders (Google, Yahoo).

What a healthy setup looks like

Check them in one pass

Rather than three separate lookups, our domain health check evaluates SPF (with recursive lookup counting), DKIM (auto-probing common selectors), DMARC (policy strength) and MX in a single report — plus SSL, blacklist, registration and DNS. If you want just the email trio, the individual SPF, DKIM and DMARC checkers share the same engine.

Fix them in the right order

  1. SPF first — publish and get under the 10-lookup limit.
  2. DKIM next — enable signing at your provider and confirm the selector resolves.
  3. DMARC last — start at p=none with reporting, fix alignment using the reports, then tighten to quarantine and reject.

Doing DMARC before SPF and DKIM are solid is how legitimate mail ends up quarantined. Build the foundation, then enforce.

Sources

Try it now — free, no signup. Check all three at once