Skip to main content
ESC
Start typing to search 370+ free tools

Email Domain Scanner

Scan a domain's complete email authentication setup in one report — MX, SPF, DKIM, DMARC, BIMI, MTA-STS, and TLS-RPT — with a score and direct links to fix anything missing.

100% Free Live DNS Scan One Report, All Records
Scan a Domain
Secure by designYour domain is processed instantly over an encrypted connection and never stored on our servers.
Encrypted in transitSubmitted over HTTPS/TLS — nothing is sent in plain text.
Never storedThe domain you check and its results are not saved to any database or log.
No third-party sharingYour data is never shared with ads, trackers, or outside services.
Processed instantlyChecked on request and discarded immediately after the response.

About Email Domain Scanner

What Is an Email Domain Scanner?

An email domain scanner checks a domain's email-related DNS setup in one pass — MX records, SPF, DKIM, and DMARC — giving you a consolidated view of whether the domain is properly configured to send and authenticate email.

How to Use the Email Domain Scanner

  • Enter the domain you want to scan
  • Click Scan
  • Review the MX, SPF, DKIM, and DMARC results
  • Fix any missing or misconfigured records

Key Features

  • All email auth records checked together — MX, SPF, DKIM, DMARC in one scan
  • Clear pass/fail per record

Who Uses This Tool

Email deliverability specialists audit domain email setup. System administrators verify configuration after setting up a new mail service.

Frequently Asked Questions

Why does proper email authentication matter?
Missing SPF, DKIM, or DMARC records make it easier for spammers to spoof your domain, and can also cause your legitimate emails to land in recipients' spam folders.

Is this tool free?
Yes, scanning an email domain is completely free.

Frequently Asked Questions

What's the difference between this and checking each record individually?
This scanner runs every check in one pass and gives you an overall score, so you can see your whole email authentication posture at a glance instead of testing SPF, DKIM, DMARC, and BIMI separately.
How is the score calculated?
Points are awarded for each correctly configured record (MX, SPF, DKIM, DMARC, BIMI), with extra weight for an enforced DMARC policy and a penalty for having multiple SPF records. It's a general health signal, not an official industry standard.
Do I need a perfect score?
No — MX, SPF, DKIM, and an enforced DMARC policy cover the fundamentals most domains need. BIMI is a bonus that requires the others to already be solid, so it's fine to tackle last.
My DKIM check failed but I know DKIM is set up.
DKIM records live at a selector-specific subdomain that isn't discoverable in DNS. This scan tries common selectors automatically; if your provider uses a custom one, check it individually with the SPF, DKIM & DMARC Checker, which accepts a custom selector.
Where do I start fixing issues?
Start with MX and SPF, then DKIM, then DMARC (beginning at policy "none" and moving to enforcement once reports look clean). Add BIMI last, once DMARC is enforced.
Is this scan safe to run on any domain?
Yes — it only reads publicly available DNS records. It doesn't send email, doesn't require any access to the domain, and doesn't store what you scan.
What are MTA-STS and TLS-RPT?
MTA-STS forces incoming mail to your domain to be delivered over encrypted TLS, preventing downgrade and interception attacks. TLS-RPT reports when those encrypted deliveries fail. Both are optional, more advanced than SPF/DKIM/DMARC, and worth adding once your core authentication is solid.

300+ Free SEO Tools — No Signup Needed

Keyword research, backlink checker, plagiarism detector, meta tags & more. All free, all instant.

Explore All Tools