Enter a domain or email and we’ll check your DMARC, SPF, and DKIM records — then explain what they mean in plain English.
We only look up public DNS records. We don’t store your domain or send you spam.
DMARC doesn't work alone. It builds on SPF and DKIM to tell inbox providers what to do when something looks wrong.
SPF is a list in your DNS of mail servers permitted to send email for your domain. If someone sends from a server not on that list, receivers may flag or reject it.
Think of it as a guest list for your domain's outbound mail.
DKIM adds a digital signature to outgoing mail. Receiving servers verify it against a public key in your DNS — confirming the message wasn't altered in transit.
Like a wax seal on a letter.
DMARC tells inbox providers what to do with mail that fails SPF or DKIM: monitor (none), quarantine, or reject. It also tells them where to send reports about who's sending as you.
It's the bouncer checking the guest list and wax seal.
Without DMARC, SPF, and DKIM, attackers can impersonate your company — and major inbox providers are tightening authentication requirements. See what a realistic spoofed email looks like in Outlook.
View spoof email previewMost businesses have more senders than they realize. Every service that sends as your domain needs to be in your SPF record and signing with DKIM.
The checker shows what’s missing. If you want it handled, Network26 does the standard single-domain setup: review, publish, and 30 days of watching.