Skip to content

Free DMARC analyzer

Check any domain's DMARC, SPF and DKIM setup in one click: posture score, detected issues and concrete steps toward p=reject. No account, nothing to install.

How it works

  1. 1

    Enter a domain

    The domain name is enough — the part after the @ in an email address. No account, no proof of ownership, no DNS change: the analysis only reads public records.

  2. 2

    Public DNS lookup

    The analyzer queries the DMARC record published under _dmarc, the domain's SPF record and the most widely used DKIM selectors, then expands every SPF include to count the DNS lookups actually consumed.

  3. 3

    Verdict and action plan

    The result shows a posture score out of 100, the state of each protocol and the list of issues found. Thomas, the virtual CISO, then walks through the remediation path step by step and answers questions along the way.

Why analyze a domain

Without an enforced DMARC policy, nothing stops a third party from sending messages that display your domain name in the From field: receiving servers have no way to tell them apart from yours. Publishing a record is not enough either — many domains stop at p=none, an observation policy that collects reports but blocks nothing. The analysis says within seconds which side of that line a domain sits on, and what is missing to cross it.

Domain impersonation

Without an enforcing policy, the domain can front phishing or payment-fraud campaigns, at the expense of the customers and partners who recognize the name.

Legitimate mail blocked

An SPF record beyond ten DNS lookups, a revoked DKIM key or broken alignment make authentication fail for perfectly legitimate mail: invoices, notifications, campaigns.

Deliverability decay

Major mailbox providers now require a published DMARC policy from bulk senders. A non-compliant domain sees its messages diverted to the spam folder, with no warning and no notification.

What the analysis measures

DMARC does not work on its own: it builds on SPF and DKIM, and above all on alignment between the domain the recipient sees and the domain that was actually authenticated. A message can pass SPF and still fail DMARC when the two differ — by far the most common cause of unexpected failures. The analyzer therefore reports the three building blocks together: the published DMARC policy (none, quarantine or reject) and the share of traffic it applies to, the validity of the SPF record and the number of DNS lookups it consumes, and finally the DKIM selectors found along with the state of their keys. The presence of an aggregate report address is checked too: without one, the policy is published blind.

Key pointA p=none policy blocks nothing: it exists to observe before enforcing. Protection starts at p=quarantine and is only complete at p=reject applied to 100% of traffic.

How the analyzer works

Everything happens on public DNS records — the same ones any mail server reads to evaluate an incoming message. No server belonging to the domain is probed, no message is sent, nothing is modified: the analysis is strictly passive, and can therefore target a domain nobody owns here, such as a supplier's, a customer's or an acquisition target's. SPF records are expanded recursively, include after include, to count real DNS lookups rather than visible lines alone. DKIM selectors are searched among those most common at mailbox providers and email service providers: a custom selector can escape that search without the configuration being at fault, and the result says so rather than concluding that DKIM is absent.

Frequently asked questions

Is the analysis really free?
Yes, and no account is needed. The full result appears immediately: posture score, per-protocol detail, issues found and the remediation path. The free account only covers what comes next — receiving aggregate reports and tracking progress over time.
Can a domain that is not ours be analyzed?
Yes. DMARC, SPF and DKIM records are public by design: they must be readable by every mail server in the world to do their job. Analyzing a supplier's or a partner's domain therefore requires no authorization.
What does the posture score mean?
It sums up authentication strength out of 100: severity of the DMARC policy, validity of SPF, presence of DKIM keys, collection of reports. A high score reflects a configuration that is coherent and enforced, not merely records that exist.
Does the analysis change anything on the domain?
No. No writes, no connection to the servers of the domain, no test message. The operation is limited to read-only DNS queries, identical to those a receiving server runs on every message it accepts.
What comes after the diagnosis?
First fix whatever breaks authentication for legitimate mail, then publish a DMARC policy in observation mode with a report address, read those reports until every sending source is accounted for, and tighten gradually toward p=reject. The path shown under the result walks through these steps in order.

A domain that is protected, not merely configured

Analyze a domain

Free and instant — public DNS lookup, no account required.