🔍 Email Security Analyzer
Perform comprehensive email security analysis including SPF, DKIM, and DMARC validation in a single check.
How the score is worked out
This page queries live DNS. Your domain goes to SimpleMoney's network-tools API, which runs three lookups in parallel and adds up fixed points for each record it finds:
example.com TXT -> SPF 33
default._domainkey... TXT -> DKIM 33
_dmarc.example.com TXT -> DMARC 34
----
100
100 reads Excellent, 66 or more Good, 33 or more Fair, below that Poor. The full
record text for all three comes back under details, so you can read the
actual SPF mechanisms and DMARC policy rather than just the headline number.
What the number does not tell you
- The DKIM leg tries only the
defaultselector. There is no way to enumerate selectors from a domain name, so a domain signing correctly withgoogleorselector1loses 33 points here. Use the DKIM Checker with your real selector before believing that column. - Presence is not enforcement. A DMARC record of
v=DMARC1; p=none;scores the same 34 asp=reject, yet asks receivers to do nothing about spoofed mail. - Nor is presence correctness. An SPF record can be found and still
fail in use - past ten DNS lookups, or ending in
+all, which permits the entire internet.
Frequently asked questions
Why does it say DKIM missing when I know DKIM works?
Because it checks default._domainkey only. Your provider almost
certainly uses a different selector - read the s= tag in a
DKIM-Signature header of your own mail and look that one up directly.
What order should I set these up in?
SPF first, since it is one record and takes minutes. DKIM next, because it survives
forwarding where SPF does not. DMARC last, starting at p=none so the
reports show you anything you missed before you enforce.
Does a 100 score stop people spoofing my domain?
Only if the DMARC policy is at quarantine or reject. Records that merely exist give
receivers no instruction, and the score cannot see the difference. Open the DMARC
details and read the p= value.