Email Tools
DMARC Lookup
See how receivers are told to handle mail that fails SPF and DKIM for this domain.
DMARC tags at a glance
| Tag | Meaning |
|---|---|
| p | Policy for the domain: none (monitor), quarantine (spam folder), or reject. |
| sp | Policy for subdomains. Uses p when not set. |
| rua | Where daily aggregate reports are sent. |
| ruf | Where individual failure reports are sent. Many providers no longer send these. |
| pct | Percentage of failing mail the policy applies to. Default 100. |
| adkim / aspf | Alignment mode: r (relaxed, subdomains allowed) or s (strict, exact match). |
Want the complete picture? The Full Email Check scores SPF, DKIM, DMARC, MTA-STS, TLS reporting, and BIMI together.
Why this matters: what happens without SPF, DKIM, and DMARC
Email was designed without any way to prove who sent a message. SPF, DKIM, and DMARC add that proof. Inbox providers now rely on them to decide whether your mail reaches the inbox, lands in spam, or is refused outright.
| Record | What it does | Without it |
|---|---|---|
| SPF | Lists the servers and services allowed to send email as your domain, such as Microsoft 365, Google Workspace, your CRM, and your website. | Receivers cannot tell your real mail from a forgery. Mail sent through a service you forgot to list fails the check. |
| DKIM | Adds a digital signature to each message, proving it came from your domain and was not altered on the way. | Forwarded mail and mail from marketing platforms often fails authentication, and the message carries no proof of origin. |
| DMARC | Tells receivers what to do when a message fails SPF and DKIM, and sends you reports showing who is sending as your domain. | Anyone can send email that appears to come from your domain, and you have no visibility of it. |
The inbox providers now require them
Google (Gmail) and Yahoo began enforcing sender requirements in 2024, and Microsoft (Outlook.com, Hotmail, and Live) followed in 2025. Every sender needs SPF or DKIM. Businesses that send in volume, including newsletters, invoices, and CRM campaigns, need all three, with DMARC published and the From address aligned with SPF or DKIM. Mail that does not meet these requirements is increasingly sent to spam or rejected, and the rules continue to tighten.
What it costs a business
What "done right" looks like
One SPF record listing every service that sends as your domain, within the 10-lookup limit. DKIM signing enabled with a 2048-bit key for each sending service. DMARC published with reports going to a monitored address, then moved from p=none to p=quarantine or p=reject once the reports confirm all legitimate mail passes. Moving too fast blocks your own mail, so the change should be made with the reports in hand.
Our technicians correct DNS and email authentication records every day. Tell us about your domain and we will make the changes, confirm they work, and explain what we did.