SPF & DMARC Checker for your domain

Please provide a valid URL (https://www.example.com).
HTTP Basic Auth For password-protected websites (.htaccess)
Premium Plan Feature
Upgrade

Email security checked automatically and graded from A to F

SPF, DMARC and DKIM test – 100% online and free
Thousands of website owners trust InspectWP

What does the SPF & DMARC Checker cover?

SPF record including a count of DNS lookups against the RFC limit of 10

DMARC policy – detects whether p=none renders your protection ineffective

DKIM signing keys across 15 common selectors

Transport encryption: STARTTLS, MTA-STS, TLS-RPT and DANE

MX servers and certificates including remaining validity and certificate chain

An overall grade from A to F with a transparent breakdown of the points

How the email security check works

4 steps to a complete assessment of your email configuration

  1. 1 Step 1

    Enter the URL

    Enter the address of your website. The email domain to be checked is derived from it automatically.

  2. 2 Step 2

    Read the DNS records

    InspectWP queries the SPF, DMARC, DKIM, MTA-STS, BIMI, TLS-RPT and MX records of your domain and validates each record for syntax errors.

  3. 3 Step 3

    Test the mail servers

    For the most important MX servers, a real SMTP connection is opened to check STARTTLS, TLS version and certificate.

  4. 4 Step 4

    Get the result and your grade

    You get every record in plain language, an overall grade from A to F and concrete pointers on which setting to change next.

These email records are checked

Each record has its own job – only together do they add up to effective protection

SPF
Baseline protection
Defines which servers may send email in the name of your domain. The record may trigger no more than 10 DNS lookups – beyond that, receiving servers treat it as broken and ignore it.
DMARC
Highest weighting
Tells receiving servers what to do with messages that fail SPF and DKIM. Without DMARC, SPF and DKIM largely remain without consequence.
DKIM
Baseline protection
Signs outgoing messages cryptographically so that tampering in transit becomes apparent. The selector is not standardised, which is why InspectWP checks 15 common names.
STARTTLS
Transport security
Encrypts the connection between the sending and the receiving mail server. InspectWP tests this with a real SMTP connection, not just on the basis of DNS records.
MTA-STS
Transport security
Obliges sending servers to deliver your mail exclusively over an encrypted connection. Both the DNS record and the availability of the policy file are checked.
DANE
Advanced
Anchors your mail server's certificate in DNS and thereby protects against substituted certificates. Only meaningful with DNSSEC active – without DNSSEC the check is not scored.
TLS-RPT
Monitoring
Lets you receive reports when encrypted delivery to your domain fails. Without these reports, transport problems go unnoticed.
BIMI
Brand impact
Displays your brand logo next to the message in the inbox. It requires an already enforced DMARC policy and therefore acts as confirmation of a clean configuration.

How your grade from A to F is calculated

The score is not an estimate but a weighted point calculation

Check Points Scoring
DMARC 30 p=reject full points, p=quarantine two thirds, p=none one third
SPF 25 Full points below 8 lookups, a deduction from 8 onwards, a clear deduction above the RFC limit of 10
DKIM 25 Full points as soon as a valid signing key is found
STARTTLS 15 Full points if every checked server encrypts – proportional if only some of them do
MTA-STS 10 Full points with an enforced policy (mode enforce), 7 in testing mode, 5 for the DNS record alone or mode none
BIMI 10 Full points for a valid record
DANE 5 Only scored if DNSSEC is active for the domain
TLS-RPT 5 Full points for a configured reporting address

What the grades mean

  • A 85% and up

    Exemplary configuration – spoofing protection and transport encryption are in effect

  • B 70–84%

    Solid foundation, individual additional features are still missing

  • C 50–69%

    Baseline protection in place, but with noticeable gaps

  • D 28–49%

    Only fragments configured – abuse of the domain is a realistic prospect

  • F below 28%

    No effective protection – your domain can be forged practically at will

Checks that were technically impossible to run do not enter the calculation in the first place. If your mail servers reject connections from our test IP, for example, that does not lower your grade – the points simply drop out on both sides.

The three DMARC policies compared

The most common mistake is not a missing record, but an ineffective one

  • p=none

    Receiving servers continue to deliver forged messages and merely send you reports. Useful as a transitional state during rollout – as a permanent state it offers no protection.

    Suitable only as a starting point
  • p=quarantine

    Messages that fail the check land in the spam folder. A good intermediate step once the reports show you that your own sending paths are clean.

    Sensible intermediate step
  • p=reject

    Forged messages are already rejected at acceptance and never reach the recipient. This is the goal of every DMARC rollout and earns full points in the score.

    Recommended target
Email security check – SPF, DMARC and DKIM test for a domain

Prevent email spoofing with the SPF & DMARC Checker

Without correctly configured SPF, DKIM and DMARC records, practically anyone can send email in the name of your domain. Recipients see your sender name while the message originates from a foreign server – the classic starting point for phishing and invoice fraud. The InspectWP email check reads every relevant DNS record of your domain, validates its syntax and tells you in plain language which gap an attacker could exploit. A particularly common case: a DMARC record does exist, but it is set to p=none and therefore explicitly instructs receiving servers to deliver forged messages anyway.

Transport encryption and the security score

SPF, DKIM and DMARC answer the question of who is allowed to send in your name. Whether the message can be read in transit is decided by transport encryption. To test this, InspectWP opens a real SMTP connection to your mail servers and checks whether they offer STARTTLS, which TLS version they speak and how long their certificate remains valid. MTA-STS, TLS-RPT and DANE are evaluated on top of that. All individual results feed into a score with a grade from A to F – whereby checks that were technically impossible to run neither improve nor worsen the rating.

Email security score – assessment of the domain configuration

Thousands of website owners trust InspectWP

The numbers speak for themselves

0+
Websites analyzed
0+
Plugins detected
0+
Themes detected

Frequently asked SPF & DMARC Checker questions

Everything you need to know about the email security test

The three complement each other: SPF defines which servers may send in your name. DKIM signs every message cryptographically so that changes in transit become apparent. DMARC ties both together and tells the recipient what to do when a check fails. Without DMARC, SPF and DKIM largely remain without consequence, because no recipient knows how to react.
Your registration could not be saved. Please try again.
Your registration was successful.

Newsletter

Subscribe to our newsletter to stay up to date.

We use Sendinblue as our marketing platform. By completing and submitting the form, you acknowledge that the information you have provided will be sent to Sendinblue for processing in accordance with Terms of Use.