SPF, DKIM and DMARC Validator
Analyze a domain's anti-spoofing configuration: SPF validity (10-lookup limit), DMARC policy and DKIM keys for common selectors.
How it works
SPF, DKIM and DMARC protect your domain against email address spoofing. SPF (TXT "v=spf1") lists the servers allowed to send for your domain; if it contains more than 10 mechanisms requiring a DNS resolution, mail servers reject it (permerror). DKIM cryptographically signs messages using a key published in a TXT "selector._domainkey" record. DMARC (TXT "_dmarc") indicates what to do when SPF or DKIM fails (monitor, send to spam, reject).
A complete configuration combines all three: SPF with "~all" or "-all", DKIM active at every sender, and DMARC with "p=quarantine" or "p=reject" to actually block spoofing.
Examples
Frequently asked questions
What is the 10-lookup SPF limit?
RFC 7208 limits to 10 the number of SPF mechanisms that trigger a DNS resolution (include, a, mx, ptr, exists, redirect). Beyond that, servers return "permerror" and reject the SPF.
Can I have several SPF records?
No: two TXT records starting with "v=spf1" cause a permerror. All mechanisms must fit in a single record.
What is DMARC for if I already have SPF and DKIM?
DMARC tells servers what to do with unauthenticated messages and sends you reports. Without DMARC, an SPF/DKIM failure often has no consequence.
Why is no DKIM selector detected?
Selectors are specific to each provider (for example "s1" at a mail gateway, "google" at Google Workspace). The tool tests the most common ones; a custom selector remains possible.
What does p=none mean?
Monitoring policy: DMARC collects reports but blocks nothing. It is the recommended stage before moving to quarantine and then reject.