SPF & DMARC Checker for your domain
Email security checked automatically and graded from A to F
What does the SPF & DMARC Checker cover?
SPF record including a count of DNS lookups against the RFC limit of 10
DMARC policy – detects whether p=none renders your protection ineffective
DKIM signing keys across 15 common selectors
Transport encryption: STARTTLS, MTA-STS, TLS-RPT and DANE
MX servers and certificates including remaining validity and certificate chain
An overall grade from A to F with a transparent breakdown of the points
How the email security check works
4 steps to a complete assessment of your email configuration
-
1 Step 1
Enter the URL
Enter the address of your website. The email domain to be checked is derived from it automatically.
-
2 Step 2
Read the DNS records
InspectWP queries the SPF, DMARC, DKIM, MTA-STS, BIMI, TLS-RPT and MX records of your domain and validates each record for syntax errors.
-
3 Step 3
Test the mail servers
For the most important MX servers, a real SMTP connection is opened to check STARTTLS, TLS version and certificate.
-
4 Step 4
Get the result and your grade
You get every record in plain language, an overall grade from A to F and concrete pointers on which setting to change next.
These email records are checked
Each record has its own job – only together do they add up to effective protection
- SPF Baseline protection
- Defines which servers may send email in the name of your domain. The record may trigger no more than 10 DNS lookups – beyond that, receiving servers treat it as broken and ignore it.
- DMARC Highest weighting
- Tells receiving servers what to do with messages that fail SPF and DKIM. Without DMARC, SPF and DKIM largely remain without consequence.
- DKIM Baseline protection
- Signs outgoing messages cryptographically so that tampering in transit becomes apparent. The selector is not standardised, which is why InspectWP checks 15 common names.
- STARTTLS Transport security
- Encrypts the connection between the sending and the receiving mail server. InspectWP tests this with a real SMTP connection, not just on the basis of DNS records.
- MTA-STS Transport security
- Obliges sending servers to deliver your mail exclusively over an encrypted connection. Both the DNS record and the availability of the policy file are checked.
- DANE Advanced
- Anchors your mail server's certificate in DNS and thereby protects against substituted certificates. Only meaningful with DNSSEC active – without DNSSEC the check is not scored.
- TLS-RPT Monitoring
- Lets you receive reports when encrypted delivery to your domain fails. Without these reports, transport problems go unnoticed.
- BIMI Brand impact
- Displays your brand logo next to the message in the inbox. It requires an already enforced DMARC policy and therefore acts as confirmation of a clean configuration.
How your grade from A to F is calculated
The score is not an estimate but a weighted point calculation
| Check | Points | Scoring |
|---|---|---|
| DMARC | 30 | p=reject full points, p=quarantine two thirds, p=none one third |
| SPF | 25 | Full points below 8 lookups, a deduction from 8 onwards, a clear deduction above the RFC limit of 10 |
| DKIM | 25 | Full points as soon as a valid signing key is found |
| STARTTLS | 15 | Full points if every checked server encrypts – proportional if only some of them do |
| MTA-STS | 10 | Full points with an enforced policy (mode enforce), 7 in testing mode, 5 for the DNS record alone or mode none |
| BIMI | 10 | Full points for a valid record |
| DANE | 5 | Only scored if DNSSEC is active for the domain |
| TLS-RPT | 5 | Full points for a configured reporting address |
What the grades mean
-
A 85% and up
Exemplary configuration – spoofing protection and transport encryption are in effect
-
B 70–84%
Solid foundation, individual additional features are still missing
-
C 50–69%
Baseline protection in place, but with noticeable gaps
-
D 28–49%
Only fragments configured – abuse of the domain is a realistic prospect
-
F below 28%
No effective protection – your domain can be forged practically at will
Checks that were technically impossible to run do not enter the calculation in the first place. If your mail servers reject connections from our test IP, for example, that does not lower your grade – the points simply drop out on both sides.
The three DMARC policies compared
The most common mistake is not a missing record, but an ineffective one
-
p=none
Receiving servers continue to deliver forged messages and merely send you reports. Useful as a transitional state during rollout – as a permanent state it offers no protection.
Suitable only as a starting point -
p=quarantine
Messages that fail the check land in the spam folder. A good intermediate step once the reports show you that your own sending paths are clean.
Sensible intermediate step -
p=reject
Forged messages are already rejected at acceptance and never reach the recipient. This is the goal of every DMARC rollout and earns full points in the score.
Recommended target
Prevent email spoofing with the SPF & DMARC Checker
Without correctly configured SPF, DKIM and DMARC records, practically anyone can send email in the name of your domain. Recipients see your sender name while the message originates from a foreign server – the classic starting point for phishing and invoice fraud. The InspectWP email check reads every relevant DNS record of your domain, validates its syntax and tells you in plain language which gap an attacker could exploit. A particularly common case: a DMARC record does exist, but it is set to p=none and therefore explicitly instructs receiving servers to deliver forged messages anyway.
Transport encryption and the security score
SPF, DKIM and DMARC answer the question of who is allowed to send in your name. Whether the message can be read in transit is decided by transport encryption. To test this, InspectWP opens a real SMTP connection to your mail servers and checks whether they offer STARTTLS, which TLS version they speak and how long their certificate remains valid. MTA-STS, TLS-RPT and DANE are evaluated on top of that. All individual results feed into a score with a grade from A to F – whereby checks that were technically impossible to run neither improve nor worsen the rating.
Thousands of website owners trust InspectWP
The numbers speak for themselves
Frequently asked SPF & DMARC Checker questions
Everything you need to know about the email security test
More tools you might need
These checks cover related topics