One domain in, one honest number out. The score aggregates the email authentication checks receivers actually see — with published weights, a completeness figure, and zero guarantees about inbox placement.
Standard mode checks MX, SPF, DMARC and (optionally) a DKIM selector. Deep mode adds common DKIM selectors, BIMI, MTA-STS/TLS-RPT, FCrDNS and public blocklists.
We query public DNS (and, in deep mode, a bounded set of public blocklists and HTTPS policy files) for the domain you enter. The domain is used only to run the analysis; nothing you submit is persisted.
Standard mode checks MX, SPF, DMARC and an optional DKIM selector with a short query budget. Deep mode adds a bounded common-selector DKIM scan, BIMI, MTA-STS/TLS-RPT, FCrDNS and the reviewed public blocklist set. The toggle changes the real server-side check set, not just a label.
The analysis calls the same shared check libraries that power the dedicated SPF, DKIM, DMARC, BIMI, MTA-STS and blacklist tools — no shortcuts and no reimplemented parsers. DNS answers are deduplicated within a run, and every query budget is bounded and documented.
Standard: MX 15, SPF 25, DKIM 30, DMARC 30. Deep: MX 10, SPF 20, DKIM 25, DMARC 25, blocklists 10, MTA-STS & TLS-RPT 5, BIMI 3, FCrDNS 2. Pass earns full weight, warning half, failure zero; the total is scaled to 100 over the checks that could actually be evaluated.
Timeouts and failed lookups are excluded from the score and surfaced through a completeness percentage, so a flaky DNS day degrades your confidence rather than inflating your score. Critical blockers and a severity-ordered remediation list come with the number.
One-click pass/fail validation of MX, SPF, DKIM and DMARC with deep links into every finding.
Open toolA wider security-configuration audit of the same domain, with findings sorted into a remediation plan.
Open toolInspect the DMARC record behind the largest single weight in the score, validated against RFC 9989.
Open toolRun the reviewed public DNSBL/RHSBL checks on their own with per-provider delisting evidence.
Open toolThe score is a transparent, published-weight formula over the checks that produced a definite result. Standard mode weights: MX 15, SPF 25, DKIM 30, DMARC 30 (total 100). Deep mode weights: MX 10, SPF 20, DKIM 25, DMARC 25, public blocklists 10, MTA-STS & TLS-RPT 5, BIMI 3, FCrDNS 2 (total 100). A passing check earns its full weight, a warning earns half, a failure earns zero, and the result is scaled to 100 over the checks that could be evaluated. Checks that timed out or could not run are excluded from the denominator and lower the reported completeness instead of being silently counted as passes.
No, and we never claim it does. The score measures the health of your public email configuration — the DNS records receivers use to authenticate and route your mail. Inbox placement also depends on engagement, complaint rates, sending history, message content and per-provider reputation, none of which public DNS can reveal. Treat the score as a hygiene check: fix the failures it reports, but do not read it as a deliverability prediction.
Standard mode runs a short, fast pass: MX records, SPF, DMARC and — if you supply a selector — DKIM, with a small bounded query budget. Deep mode keeps those checks and adds a bounded scan of 12 common DKIM selectors (when you did not supply one), a BIMI check with its DMARC prerequisite, MTA-STS policy and TLS-RPT reporting, forward-confirmed reverse DNS of your MX hosts, and the reviewed set of public IP and domain blocklists. Deep mode uses a larger but still capped query and time budget, so it can take up to about a minute.
DNS is a live network: lookups can time out and some providers refuse queries from public resolvers. When a check cannot finish, the tool reports it as unknown and removes its weight from the score denominator, then shows what fraction of the total weight was actually evaluated as the completeness percentage. A score of 95 with 60% completeness is weaker evidence than a 95 with 100% completeness — always read the two together.
BIMI only works once DMARC enforces at p=quarantine or p=reject, so a missing or weak DMARC record already fully explains why a BIMI logo would not display. Scoring BIMI as a separate failure on top of the DMARC failure would penalize the same root cause twice, so the tool reports BIMI as "not run" in that situation and points you at the DMARC fix first.
Deep mode queries a reviewed registry of active, publicly documented DNSBL and RHSBL zones — only zones that are live, keyless and documented by their operators are included, and dead or restricted lists are deliberately excluded. Public blocklists are only one signal: major mailbox providers keep their own private reputation systems that no public tool can query. A clean result here is encouraging, not proof of clean ISP reputation, and an inconclusive (timed-out) provider answer is never counted as clean.
Automate Sales Outreach & Get Booked!
Start Free Trial(14 Day Free Trial, No CC Required)