Email Authentication Checker: SPF, DKIM, and DMARC
Check a domain's SPF, DKIM, DMARC, and MX records and get plain-language fixes for every gap. Free, no sign-up, results in seconds.
Free with no sign-up. Checks run in your browser. To read your domain's records, the name you enter is sent to Google Public DNS; nothing is sent to Tutti or stored.
Check a domain
A DKIM selector is the name your provider uses for its signing key. The common ones are checked already; add yours if you know it.
How it works
- Enter your domain, for example yourcompany.com.
- The tool reads its public DNS records: SPF, DMARC, common DKIM selectors, and MX.
- Each setting gets a plain verdict: good, improve, or missing, with the record it found.
- Every gap comes with a short explanation of what it means and what to change.
Why these records decide inbox placement
SPF says which servers may send as your domain. DKIM signs each message so receivers can tell it was not changed in transit. DMARC tells receivers what to do when either check fails, and where to report. Together they are how Gmail, Outlook, and company filters decide whether mail from your domain is real. Missing records make spoofing easy and push even legitimate mail toward spam.
If something is missing, build the exact record with the SPF and DMARC record generator, then work through the deliverability checklist for the rest of the setup.
Frequently asked questions
What do SPF, DKIM, and DMARC actually do?
SPF lists the servers allowed to send as your domain. DKIM signs each message so receivers can confirm it was not altered. DMARC tells receivers what to do when SPF or DKIM fails, and where to send reports. Together they make spoofing your domain much harder and help legitimate mail reach the inbox.
Why is p=none a warning?
A DMARC policy of p=none only collects reports. Failing messages are still delivered, so the record is useful for monitoring but not yet protecting the domain. Once reports look clean, move to p=quarantine and then p=reject.
The tool says no DKIM key was found. Is it really missing?
Not necessarily. DKIM keys live under a selector chosen by your email provider, and providers use different names. The checker tries common selectors; if yours is custom, enter it in the selector field or ask your provider which selector to use.
Do I need all of this for normal email?
Authentication helps every sender, and bulk senders must meet the provider guidelines: Google and Yahoo require SPF or DKIM plus DMARC for high-volume sending to personal inboxes. DMARC reporting is the part most small senders skip first.
Answer every email. Approve every send.
Connect Gmail, name your labels, and approve your first AI draft today.
14-day free trial
No credit card
Nothing sends without approval
Disclaimer: these free tools are provided for general information only, as-is and without warranties of any kind. They are not legal, compliance, security, financial, or other professional advice, and no result is a guarantee that a message will be delivered, accepted, or compliant. You are responsible for reviewing every result before relying on it or sending anything based on it. To the maximum extent permitted by law, Tutti accepts no liability for any loss or damage arising from the use of these tools or from reliance on their output. Your use is also governed by our Terms of Service.