What this test can tell you
- The free checker reads public SPF, DMARC, MX and selected DKIM DNS records.
- Its 0–100 score is a Valydex DNS configuration heuristic, not a verified security grade or deliverability guarantee.
- A missing DKIM result may mean the actual selector was not tested; enter the selector from your mail provider.
- Verify real sent-message headers and DMARC reports before enforcing a policy.
Last updated: September 24, 2026
The checker is a useful inventory prompt. It does not send a test email, inspect every DKIM selector, prove SPF/DKIM alignment for each mail service or establish that your domain cannot be spoofed. It queries selected public DNS records and scores their configured status. Microsoft's authentication operations guide distinguishes published records from actual message results; use both views.
Run a trustworthy baseline check
- Enter your primary sending domain in the Email Security Checker. If you know the active DKIM selector, enter it. Save the record output and date.
- List every service that sends from that domain: human mail, CRM, invoices, marketing, website forms and help desk. Include subdomains that send separately.
- From each service, send a real message to a mailbox where you can inspect authentication headers. Record SPF, DKIM and DMARC results and the visible From domain.
- Compare failures with provider documentation. Fix the service or DNS configuration, retest the message, then watch aggregate reports.
- Recheck after new vendors, DNS changes, mail routing changes or key rotation.
| Checker result | What it means | What to verify next |
|---|---|---|
| SPF record exists | A public sender policy was found | All legitimate senders are included; actual mail passes and aligns |
| DKIM key found for a selector | That public key is published | The provider signs with that selector and real messages verify |
| No DKIM key found | No key for the selectors tested | The provider's actual selector, including a custom one |
| DMARC policy exists | A policy is published | Real-message alignment, reporting address and handling of failures |
| MX exists | Receiving mail routing is published | Whether the domain should receive mail at all |
Do not interpret a high score as protection from lookalike domains, display-name fraud or compromised accounts. The business email security guide covers identity, filtering and payment verification alongside DNS.
Move DMARC cautiously
Use p=none to observe legitimate sending and gather aggregate data. Investigate failures by sending source. If legitimate mail is aligned and monitored, consider staged quarantine and then reject, with rollback and owner approval. Avoid copying a DNS record template into production before replacing example addresses and checking your actual providers. The FTC notes that these records take expertise to configure without blocking real mail; Google's sender guidelines explain their operational role.
Evidence to retain: sender inventory, DNS record snapshot, sample authentication headers from each service, DMARC aggregate findings, change approval and retest. That is more useful than the score alone.
Before changing an enforcement policy
Confirm where invoices, support tickets and marketing mail originate. A correct-looking policy can still reject legitimate messages if an outside sender is not aligned.
Sources checked September 24, 2026: Microsoft email-authentication operations guide, Google sender guidelines, and FTC small-business email authentication. Checker limitations were verified against the Valydex implementation; the tool is not a hands-on mail audit.