A calm domain check

Is your domain ready to reject impostors?

Get a plain-English read on the public email settings that help protect your business from spoofed messages. No passwords. No mailbox access. No alarm bells.

Public records onlyRuns in your browser

Start here

Check a domain

We only ask for a domain name. This page reads public DNS records and never needs an account or credential.

What we look for

Four records, one clearer conversation.

SPF

Which services are allowed to send as your domain.

DKIM

A cryptographic signature, if you provide its selector.

DMARC

The instruction receivers follow when something does not match.

MX + DNSSEC

Where mail goes, and whether DNS answers can be trusted.

Private by design

This checker sends only the domain and optional DKIM selectors to a public DNS-over-HTTPS resolver. It does not ask for passwords, mailbox logins, API keys or private credentials. Nothing is saved by this page.

A useful first look, not a certificate

DNS records can be incomplete, cached or specific to your mail provider. This page cannot test message delivery, mailbox configuration or selectors you did not provide. If a result is unclear, ask your provider for the exact record to publish.

Next, make sense of the settings

A DMARC record is only helpful when you know what to do with it.

Our small-business checklist explains the policy choices in plain English, including how to move from monitoring to stronger protection without guessing.

Read the DMARC small-business checklist

Good security starts with knowing what is already public.