DOMAIN SECURITY ANALYZER
SPF lookup limits, DKIM key strength, DMARC enforcement, MTA-STS policy files, DNSSEC, certificates, headers and mail server reputation — analyzed, not just detected.
SPF lookup limits, DKIM key strength, DMARC enforcement, MTA-STS policy files, DNSSEC, certificates, headers and mail server reputation — analyzed, not just detected.
No plugins. No installation. No access to your servers required.
Type your domain name. That's it. Everything is checked from the outside, exactly as a receiving mail server sees you.
5 secondsOver 20 checks across email authentication, DNS, transport security and reputation — including the ones that only fail under load.
20‑60 secondsFindings ranked by real-world risk, each with the exact record or header change needed to resolve it.
Instant reportThe checks that actually determine whether your mail arrives and your domain can be spoofed
We recursively resolve your SPF record and count every DNS lookup against the limit of 10. Exceeding it silently breaks authentication for all of your mail — and a record that merely starts with v=spf1 looks perfectly healthy to lesser tools.
DKIM keys are discovered across 82 common selectors covering Google, Microsoft, Zoho, Proton, SendGrid, Postmark and more, then decoded from DER to report true key length rather than an estimate.
Your MTA-STS policy file is retrieved over HTTPS, parsed, and matched against your live MX records. A DNS record pointing at a broken policy is reported as broken, not as a pass.