Loading network utility...
Loading network utility...
Audit your domain's email authentication posture in real-time. Verify SPF syntax and lookup limits, evaluate DMARC enforcement policies, validate DKIM public keys, and inspect MX mail routing.
Email spoofing and phishing cost organizations billions each year. Because the original Simple Mail Transfer Protocol (SMTP) lacked built-in identity verification, three interoperable standards were created to authenticate sender identity and protect domain reputation.
SPF authorizes specific mail servers by IP address or third-party includes (such as Google Workspace or SendGrid). Recipient mail transfer agents check whether the sending server's IP matches your domain's published SPF record.
DKIM signs outbound messages with an asymmetric private cryptographic key. Recipient mail servers fetch your public key via a DNS TXT record under a specific selector to mathematically verify message integrity and sender legitimacy.
DMARC requires alignment between visible "From" headers and SPF/DKIM domains. It instructs receiving mail gateways whether to deliver, quarantine, or reject failing messages, and sends automated telemetry to your reporting address.
When launching DMARC, begin in monitoring mode (p=none) to collect aggregate reports and identify legitimate services sending on your behalf. Once all legitimate senders pass SPF and DKIM alignment, escalate to enforcement:
Publishing more than one TXT record starting with v=spf1 causes an automatic PermError. Consolidate all mechanisms into a single record.
Nesting multiple third-party includes can easily cross the RFC 7208 10-lookup barrier. Use our lookup counter to monitor query counts.
Ending an SPF record with +all authorizes every server on the internet to send mail for your domain. Always use -all or ~all.
Leaving DMARC in p=none indefinitely leaves your domain vulnerable to spoofing. Use monitoring reports to fix alignment and graduate to p=reject.
Explore our dedicated DNS tools to check reported TTL, authoritative nameservers, and zone files.
High-speed, zero-cost engineering tools built for network diagnostics and developer workflows.
Detect IP, GeoIP, ISP, ASN & PTR
Reverse IP to PTR hostname & verify FCrDNS
Query A, AAAA, MX, TXT & NS records
Domain registrar & expiry info
Check global DNS record propagation across Anycast resolvers
Calculate CIDR, masks & host ranges
Deep-dive networking articles and protocol specifications related to this utility.
What is a subnet? Learn IPv4 subnetting formulas, CIDR notation (/24 to /30), bitwise AND math, broadcast addresses, and usable host calculation with diagrams.
Learn how to check open TCP ports using terminal commands (Netcat, PowerShell, lsof) and free online port scanners. Verify firewall and open port security.
What is DNS (Domain Name System)? Learn how DNS lookup works in 4 stages: Recursive Resolver, Root Server, TLD Server, and Authoritative Nameserver.