๐ ๏ธ DMARC Tools
Choose a tool from the menu above to get started.
๐ Why This Matters
Email is one of the most abused communication channels on the internet. Attackers frequently forge ("spoof") emails to impersonate trusted domains โ like banks, governments, or your company โ to trick users into clicking malicious links or giving up sensitive data.
To combat this, modern email security standards like SPF, DKIM, and DMARC were introduced:
- SPF (Sender Policy Framework): Specifies which IP addresses or servers are allowed to send emails on behalf of your domain.
- DKIM (DomainKeys Identified Mail): Ensures the message content hasnโt been altered in transit and verifies it was authorized by the sender domain.
- DMARC (Domain-based Message Authentication, Reporting, and Conformance): Builds on SPF and DKIM, allowing domain owners to declare how unauthenticated messages should be handled โ reject, quarantine, or monitor them.
๐งฐ About This Toolset
This site helps you test, validate, and simulate how these email security protocols work for your domain โ using public DNS lookups in real time. Itโs free, fast, and privacy-friendly.
๐งช Tool Descriptions
-
๐ฌ DMARC Record Checker:
Enter your domain (e.g.,example.com) to view its published_dmarcrecord. The tool explains each part of the policy and highlights issues like missing `rua`, weak policy (`none`), or misalignment. -
๐ก๏ธ SPF Record Checker:
Fetch the SPF TXT record for your domain and display its mechanisms (e.g., `ip4`, `include`, `all`). This helps ensure your authorized mail servers are correctly listed. -
๐ DKIM Record Checker:
Provide a domain and selector (e.g.,default._domainkey.example.com) to retrieve and validate the public DKIM key. This is critical for verifying DKIM is correctly deployed. -
๐ DNS Health Dashboard:
Lookup specific DNS records (A, MX, TXT, NS, etc.) to verify that your domain is reachable, properly configured, and responding with expected values. -
๐งฎ DMARC Record Generator:
Use a guided form to create a DMARC record from scratch โ selecting your policy (`none`, `quarantine`, or `reject`), adding report recipients, and choosing alignment settings. -
๐ฏ DMARC Policy Simulator:
Simulate a real-world email delivery scenario. Choose whether SPF and DKIM passed or failed, and whether they were aligned. The tool shows if DMARC would pass or fail and explains why.
๐ Privacy and Safety
This tool uses only public DNS resolvers (like Cloudflare DNS) and performs no authentication or logging. No data is stored, tracked, or shared. Itโs safe to test with real production domains.
๐ก Tips
- Use
quarantineorrejectDMARC policies in production โ avoidnoneunless you're in monitoring mode. - Publish an
ruaaddress to receive aggregate DMARC reports. - Make sure SPF and DKIM are both passing and aligned for best protection.
- Test changes after DNS propagation (can take 5โ30 minutes).