Cyber AssessValydex™by iFeelTech
Implementation Guide

Email Security Tester Guide (2026)

SPF, DKIM, and DMARC Validation Workflow

Privacy-first workflow for validating domain email authentication settings and reducing spoofing and phishing exposure.

Last updated: September 24, 2026
3 minute read

What this test can tell you

  • The free checker reads public SPF, DMARC, MX and selected DKIM DNS records.
  • Its 0–100 score is a Valydex DNS configuration heuristic, not a verified security grade or deliverability guarantee.
  • A missing DKIM result may mean the actual selector was not tested; enter the selector from your mail provider.
  • Verify real sent-message headers and DMARC reports before enforcing a policy.

Last updated: September 24, 2026

The checker is a useful inventory prompt. It does not send a test email, inspect every DKIM selector, prove SPF/DKIM alignment for each mail service or establish that your domain cannot be spoofed. It queries selected public DNS records and scores their configured status. Microsoft's authentication operations guide distinguishes published records from actual message results; use both views.

Run a trustworthy baseline check

  1. Enter your primary sending domain in the Email Security Checker. If you know the active DKIM selector, enter it. Save the record output and date.
  2. List every service that sends from that domain: human mail, CRM, invoices, marketing, website forms and help desk. Include subdomains that send separately.
  3. From each service, send a real message to a mailbox where you can inspect authentication headers. Record SPF, DKIM and DMARC results and the visible From domain.
  4. Compare failures with provider documentation. Fix the service or DNS configuration, retest the message, then watch aggregate reports.
  5. Recheck after new vendors, DNS changes, mail routing changes or key rotation.
Checker resultWhat it meansWhat to verify next
SPF record existsA public sender policy was foundAll legitimate senders are included; actual mail passes and aligns
DKIM key found for a selectorThat public key is publishedThe provider signs with that selector and real messages verify
No DKIM key foundNo key for the selectors testedThe provider's actual selector, including a custom one
DMARC policy existsA policy is publishedReal-message alignment, reporting address and handling of failures
MX existsReceiving mail routing is publishedWhether the domain should receive mail at all

Do not interpret a high score as protection from lookalike domains, display-name fraud or compromised accounts. The business email security guide covers identity, filtering and payment verification alongside DNS.

Move DMARC cautiously

Use p=none to observe legitimate sending and gather aggregate data. Investigate failures by sending source. If legitimate mail is aligned and monitored, consider staged quarantine and then reject, with rollback and owner approval. Avoid copying a DNS record template into production before replacing example addresses and checking your actual providers. The FTC notes that these records take expertise to configure without blocking real mail; Google's sender guidelines explain their operational role.

Evidence to retain: sender inventory, DNS record snapshot, sample authentication headers from each service, DMARC aggregate findings, change approval and retest. That is more useful than the score alone.

Before changing an enforcement policy

Confirm where invoices, support tickets and marketing mail originate. A correct-looking policy can still reject legitimate messages if an outside sender is not aligned.

Sources checked September 24, 2026: Microsoft email-authentication operations guide, Google sender guidelines, and FTC small-business email authentication. Checker limitations were verified against the Valydex implementation; the tool is not a hands-on mail audit.