Type a domain. We check SPF, DKIM, DMARC, MX and transport security, and explain in plain English what is wrong and how to fix it.
Every tool explains what it found, why it matters and what to do about it.
Counts the DNS lookups the way a receiver does, and names the mechanism that pushes you over the limit of ten.
DMARCReads the policy and explains alignment, which is what almost every "SPF passes but DMARC fails" ticket turns out to be.
DKIMReads the real key size out of the record, and tells a revoked key apart from a malformed one.
MXWhere your mail actually goes, and whether every host in the list resolves.
STSWhether a sender can be forced to use TLS to reach you, or can be silently downgraded.
RPTWhether you would ever hear about a TLS delivery failure to your own mail servers.
Queries resolve through resolvers we operate, in our own data centres. That is why a result can honestly say where it was resolved from, and why there is no rate limit for ordinary use.
Yes. Every tool on this site, and the full report, run without an account and without payment. Paid plans exist for continuous monitoring, which is a different thing: watching a domain over time and telling you when something changes.
No. A report link is permanent. Paste it into a ticket and it will still resolve in a year, showing what was true when the check ran.
No. Reports are not listed, indexed or shared. Anyone with the link can read it, so treat the link as you would the result itself.
Bangla is being added to the explanations and fixes, not only the interface labels. A record that is wrong should be explained in the language of whoever has to fix it.