Free forever
Email HealthChecker
Enter any domain to check its SPF, DKIM, and DMARC email authentication in real time. Free, no account needed. It reads what is public, so it sees your records and blocklist status, not your complaint rate.
14-day free trial · no credit card · cancel anytime
A health check runs the public-side checks a receiver runs before trusting your mail: SPF present and parseable, DKIM selectors that actually resolve, a DMARC policy, working MX records, and the sending IPs and domain not sitting on a blocklist.
Everything it examines is public DNS, which is the point: receivers judge your domain from public records, so any gap here is a gap every receiver sees.
How it works
- 01Enter the domain. No account, no email sent, nothing installed.
- 02The check resolves your DNS records in real time and validates each one: SPF syntax and lookup depth, DKIM selectors, DMARC policy and reporting addresses, MX shape.
- 03Mail exchanger IPs are resolved and checked against the common DNSBL zones, alongside the domain itself.
- 04You get a structured report of what passed, what failed, and what each failure means for delivery.
When to use it
Onboarding a domain you plan to send from, before the first campaign, so authentication problems are fixed before they cost reputation.
After any DNS change, provider switch or sudden drop in open rates, to rule out the public-side basics quickly.
Common mistakes
Testing SPF alone and calling it done
SPF is one of three legs. Mail without DKIM has no signature that survives forwarding, and without DMARC you have no policy and no visibility through reports. Receivers that require sender authentication check all three.
Leaving DMARC at p=none forever
A monitor-only policy gives you reports but tells receivers to do nothing with failures. Domains sit at p=none for years collecting evidence of spoofing they never act on. Move to quarantine and reject as your aligned traffic reaches stability.
Forgetting records from providers you stopped using
Old ESP includes still in SPF cost lookups and authorize servers you no longer pay for. Retired DKIM selectors left in DNS are harmless clutter, but stale SPF includes actively widen your attack surface.
Checking once and never again
Records drift: providers change IP ranges, someone re-publishes a record during a migration, a blocklist listing appears after a compromised account. A single clean check proves one moment, not a state.
Frequently asked questions
What exactly does the health check examine?
Public DNS: the SPF record (existence, syntax, lookup depth), DKIM selectors you use with your providers, the DMARC record and its policy, MX records and their IPs, and blocklist status for both the domain and those IPs. It does not send email and cannot see private metrics like complaint rates.
Does the check send any email from my domain?
No. It is entirely DNS-based: it reads the records receivers read. Nothing is sent, nothing is modified, and no sender reputation is touched.
What does a passing DMARC configuration look like?
A DMARC record on _dmarc.yourdomain with at least a p=none policy, published while you collect reports, tightened to quarantine and reject once your legitimate senders pass alignment. The health check shows which stage you are at.
Why does DKIM need a selector?
The selector is the DNS name part that points to your public key, such as s1._domainkey.example.com. Providers rotate selectors, and a check that only probes one selector can miss the one actually signing. The report shows what resolved and what did not.
How is this different from a blocklist checker?
The blocklist checker answers one question in depth: is this domain or IP listed. The health check is the broader pass over authentication, DNS shape and blocklists together, which is the right starting point when something is generally wrong.
How often should I run a health check?
After every DNS or provider change, before a large campaign on a domain that has been quiet, and on a recurring schedule otherwise. Continuous monitoring automates the recurring part with alerts when records change.
From the blog
- 550 5.7.515 in Outlook: What It Means and How to Fix It?Outlook.com bounced the email because the From domain failed a trust check. The May 2025 rule, the 5,000-a-day line, and the DNS fix.
- Why Does My Email Fail DMARC When SPF Passes?SPF checked the domain your platform mailed from, not the domain in your From line. That mismatch, not a broken record, is the usual reason DMARC fails.
Related free tools
These tools answer the question once. Continuous monitoring re-checks your domain every 6 hours and alerts you when the answer changes, from $14/mo. Pricing · Guides · FAQ
This answers once. Monitoring answers every 6 hours.
LitInboxes re-checks DNS, DMARC, and blocklists on a schedule and emails you when the answer changes. Start with a 14-day free trial.
14-day free trial · no credit card · cancel anytime
