Security tool
DNS Email Auth Checker
Check SPF and DMARC presence for your sending domain.
How it works
Email authentication records protect your domain's reputation as much as your inbox. Spoofed “support@yourproduct.com” messages erode trust faster than most product bugs. Enter a public domain (or URL - we extract the host) and we look up SPF and DMARC TXT records over Cloudflare DNS-over-HTTPS. Private and reserved hosts are rejected before lookup. SPF answers “who may send as this domain.” DMARC tells receivers what to do when SPF/DKIM fail. This teaser checks presence and a few soft signals (like a missing all mechanism). We do not validate every include: chain, DKIM selectors, BIMI, or alignment policy nuance. If SPF or DMARC is missing, add them at your DNS provider before you scale outbound email or transactional mail. Founders often configure the app login domain and forget the apex or sending subdomain. Try both www and the bare domain if results look empty. After records propagate, re-check here, then scan the live product URL with AtRisk - domain trust and application security are related stories for buyers and security questionnaires. Not a pentest or mailbox penetration exercise: public DNS only, teaser depth only.
This is a free teaser check - not a penetration test, vulnerability assessment, or compliance audit. AtRisk full scans go deeper across more detectors and unlock fix prompts on Starter.