Free tool · Domain check

Is your domain ready to send?

Enter a domain and see what mail servers see: SPF, DKIM, DMARC and MX, what each one means, and what to fix before you send a single cold email.

01What it checks

Four records decide whether you're allowed in.

Mailbox providers read them before they read a word of your email. Get one wrong and the rest of the message doesn't matter.

SPF

Which servers may send as you

One TXT record on the domain listing the services allowed to send its mail. Only one is allowed, it may cost at most 10 DNS lookups, and it should end in ~all or -all.

DKIM

A signature on every email

Your provider signs each message with a private key; the public key sits in DNS under a selector. It proves the mail wasn't changed and really came from the domain.

DMARC

What to do when both fail

A TXT record at _dmarc that tells receivers how to treat mail failing SPF and DKIM, and where to send reports. Gmail and Yahoo require one from bulk senders.

MX

Where replies go

The servers that receive mail for the domain. Without them every reply bounces — the one thing a cold email exists to get.

Read more: SPF, DKIM and DMARC explained · Cold email deliverability

02Questions

What people ask.

Why does DKIM say “unknown”?
DKIM keys are published under a name the sender picks (the selector), and DNS can't list them. We try the selectors the big providers use; if none answers, open an email you sent, find the DKIM-Signature header and enter its s= value. Amazon SES, for one, uses random selectors no checker can guess.
What do Gmail and Yahoo require?
Since February 2024, everyone needs SPF or DKIM, valid forward and reverse DNS, TLS and a spam rate under 0.3%. Anyone sending more than 5,000 a day to Gmail also needs both SPF and DKIM, a DMARC record (p=none is enough), alignment with the From domain, and one-click unsubscribe. This page checks the parts DNS can show.
Is p=none good enough?
It meets the requirement and is the right place to start: it only asks for reports. Once the reports show that all your real mail passes, move to p=quarantine, then p=reject, so nobody else can send as you.
Does this send an email or store my domain?
No. It reads public DNS records, the same ones any mail server reads, and keeps nothing. Results are cached for five minutes so a shared link doesn't repeat the lookups.
My records are fine. Why does my mail still land in spam?
Authentication is the entry ticket, not the score. Placement depends on reputation: how new the domain is, how much it sends, and whether people open, reply or complain. A new domain has to be warmed up — small volume first, to people who want the mail. That is what Mailbase does for every domain it sends from.
03Free tools

More free tools.

Deliverability, handled

Records right. Domain warmed. Then send.

Mailbase writes SPF, DKIM, DMARC and the reply MX when you add or buy a domain, then raises its volume only while real bounces and complaints stay low.