DMARC, SPF, and DKIM Record Checker
Check whether your domain’s email authentication records are published, valid, and actually protecting you. These three DNS records decide whether someone else can send email that looks like it came from your business.
Run a free scan below, then use the rest of this page to understand what your results mean and what to fix first.
Scan your domain
Enter the part of your email address after the @ sign, such as yourcompany.com, and select Scan Now. The results show what was found for each record and flag anything missing or misconfigured.
Why DMARC, SPF, and DKIM records matter for security
Email was built without any way to prove who sent a message. The From line is just text, and anyone can type your domain into it. SPF, DKIM, and DMARC are the checks the rest of the internet uses to tell your real email apart from a forgery. When they are missing or misconfigured, the people who pay for it are your staff, your clients, and your vendors.
They stop criminals from sending as your exact domain
Without an enforced DMARC policy, a scammer can send email that shows your real domain, not a lookalike, to anyone. A fake invoice, a request to update payment details, or a link to a counterfeit login page is far more convincing when it appears to come from you.
They close a common door to business email compromise
In business email compromise, criminals pose as a trusted person or company to redirect payments or pull sensitive data. Victims reported more than $3 billion in losses to it in 2025, second only to investment fraud, according to the FBI’s Internet Crime Complaint Center. A forged sender address is one of the easiest ways those schemes begin.
They keep your legitimate email out of spam
Google and Yahoo require every sender to authenticate its mail, and high-volume senders must publish SPF, DKIM, and DMARC. Microsoft began rejecting non-compliant bulk mail to Outlook.com, Hotmail, and Live.com addresses in May 2025. Missing or broken records put invoices, appointment reminders, and client updates at risk of the spam folder or an outright bounce.
They support compliance and client trust
Medical, dental, legal, and accounting practices send sensitive information by email every day. Email authentication is part of a defensible security program, cyber insurance applications and vendor security questionnaires increasingly ask about it, and DMARC reports show you every service sending mail in your name.
How SPF, DKIM, and DMARC work together
Each record answers a different question that a receiving mail server asks about a message claiming to come from your domain.
Is this server allowed to send for the domain?
Sender Policy Framework is a single DNS record listing the servers and services allowed to send your email. Receiving servers compare the sending server against that list. On its own, SPF checks a behind-the-scenes return address rather than the From address people see, and it often breaks when a message is forwarded.
Is the message genuine and unaltered?
DomainKeys Identified Mail adds a digital signature to each message a service sends for you, and the matching public key is published in your DNS. A valid signature shows your domain authorized the message and that nothing changed in transit. Every service that sends as you needs its own DKIM key.
What should happen when the checks fail?
DMARC requires SPF or DKIM to pass for the same domain shown in the From line, then tells receiving servers what to do with mail that fails: deliver it anyway (p=none), send it to spam (p=quarantine), or refuse it (p=reject). It also sends you reports on every source mailing as your domain.
SPF and DKIM prove where a message came from. DMARC turns that proof into protection. Until your policy is set to quarantine or reject, a message that fails every check can still reach the inbox.
What your scan results mean
These are the findings that come up most often, what each one means, and how to fix it.
No DMARC record
Receiving servers get no instructions for mail that fails authentication, and you get no reports. Anyone can send as your exact domain. Fix this first: publish a DMARC record at p=none with a reporting address so you can see who is sending as you.
DMARC set to p=none
Your domain is being monitored, not protected, and spoofed mail can still be delivered. Use the reports to confirm every legitimate sender passes, then move to p=quarantine and, finally, p=reject.
Missing, duplicate, or broken SPF
A domain can publish only one SPF record. A second record, a syntax error, or more than 10 DNS lookups (each include: counts toward the limit) makes SPF fail for all of your mail. Merge everything into one record and remove services you no longer use.
SPF ending in +all or ?all
+all tells the world that any server may send as you, and ?all makes no claim either way. End the record with ~all or -all instead.
DKIM not found
DKIM keys are stored under a selector name chosen by each sending service. The scan checks common selectors, so a missing result can mean DKIM signing is off, or that your provider uses a selector the scan did not try. Confirm DKIM is turned on in every service that sends as your domain.
Weak DKIM key
The DKIM standard treats signatures made with keys shorter than 1024 bits as invalid. Use 2048-bit keys wherever your provider supports them.
A safe path to DMARC enforcement
Jumping straight to p=reject can block your own legitimate email along with the forgeries. The safer approach tightens the policy in stages.
Inventory every sender
Your email platform, usually Microsoft 365 or Google Workspace, plus website forms, billing and invoicing software, CRM and newsletter tools, practice-management systems, and any copier or scanner that emails documents.
Authenticate each one
Add every legitimate service to your single SPF record, and turn on DKIM signing with your own domain inside each service.
Monitor at p=none
Publish DMARC with a reporting address, review the reports for a few weeks, and fix any legitimate source that is failing.
Enforce in stages
Once your real mail passes consistently, move to p=quarantine and then p=reject. Keep reviewing reports, because new services get added over time.
DMARC, SPF, and DKIM FAQs
What do SPF, DKIM, and DMARC do, in plain English?
SPF lists the servers allowed to send email for your domain. DKIM signs each message so receivers can confirm it is genuine and unaltered. DMARC tells receivers what to do when a message claiming to be from you fails those checks, and reports back to you on who is sending as your domain.
Do I need all three records?
Yes. SPF and DKIM each cover gaps in the other, and neither one tells a receiving server to block a forgery. DMARC relies on at least one of them passing, and it is the only record that lets you tell receivers to quarantine or reject spoofed mail.
Is it safe to scan my domain with this tool?
Yes. The checker only reads DNS records that are already public. It does not change anything on your domain and does not send any email.
Will turning on DMARC stop my own email from being delivered?
Not at p=none, which only monitors. Problems start when a policy moves to quarantine or reject before every legitimate sender is authenticated, which is why enforcement should be rolled out in stages using your DMARC reports.
We don't send marketing email. Do we still need DMARC?
Yes. Criminals spoof any domain people trust, not just domains that send newsletters. Google and Yahoo also expect every sender to authenticate its mail, so everyday messages like invoices and appointment reminders benefit too.
What about domains we own but never use for email?
Lock them down. Publish an SPF record of v=spf1 -all and a DMARC record at p=reject so those domains cannot be used to impersonate your business.
How long do DNS changes take to show up?
Usually minutes to a few hours, depending on the record's TTL and your DNS provider, though some changes can take up to 48 hours to be seen everywhere. Run the scan again after making changes to confirm them.
Can Harmony MSP fix these records for us?
Yes. Send us your scan results through our contact page or call or text (407) 720-6540. We will explain what each finding means for your business and what to fix first.
Want these records fixed instead of just flagged?
Harmony MSP can walk through your results with you, fix what the scan found, and move your domain to full DMARC enforcement without disrupting the email your business depends on. Prefer to talk it through? Call or text (407) 720-6540.