Domain Scanner

Enter a domain for a comprehensive email security audit. One scan covers mail routing, SPF, DKIM, DMARC, MTA-STS, BIMI, public blocklists and reverse DNS — and returns a transparent 0–10 security-configuration score with a prioritized fix list.

Scan an email domain

Enter a domain for a full email security audit: mail routing, SPF, DKIM, DMARC, MTA-STS, BIMI, public blocklists and reverse DNS.

We query public DNS (and a few bounded HTTPS policy files) on your behalf. The scan reads configuration only — it never opens SMTP connections.

Leave empty to probe a bounded set of common selectors. If you know your selector (it appears as s= in the DKIM-Signature header of mail you send), enter it for a direct check.

We query public DNS and a few bounded HTTPS policy/asset files on your behalf. The domain you enter is used only to run the scan; results are not stored.

How the Domain Scanner works

One deduplicated pass over public DNS

The scanner resolves A, AAAA, NS, MX and CAA once, then runs every protocol check through a shared cache — a DNS name is queried at most once per scan, keeping the whole audit under a documented query budget.

Every authentication layer is evaluated

SPF (with nested includes and the 10-lookup limit), DKIM at your selector or a bounded common-selector scan, DMARC with the RFC 9989 tree walk, MTA-STS with TLS-RPT, and BIMI with its DMARC prerequisite.

Public signals and reverse DNS are observed

Domain blocklists (RHSBL) and resolved-IP lists are checked against the reviewed public provider set, and MX hosts get forward-confirmed reverse DNS observations.

You get a score, evidence and a fix list

Each category earns its published weight; unknown results are excluded from the denominator and shown as completeness. Findings are merged and de-duplicated into a prioritized remediation plan with links to the dedicated checkers.

What this scan does and does not tell you

  • The 0–10 score is a DNS security-configuration score. It is not sender reputation, not a mailbox-provider score, and not a guarantee of inbox placement.
  • Public blocklist results are not a complete ISP reputation view; some providers also refuse queries from public resolvers, which is reported as unknown, never as clean.
  • A DKIM selector the common scan does not know about stays unknown — an undiscovered selector is not proof DKIM is missing. Enter your selector for a definite answer.
  • BIMI is marked not applicable until DMARC enforces, so the score never double-penalizes the same root cause.
  • DNS timeouts and failures are shown as unknown and excluded from the denominator; the completeness percentage tells you how much of the score is evidence-based.
  • The scan reads configuration only: it opens no SMTP connections, performs no STARTTLS delivery test, and cannot prove what a specific receiver did with a specific message.

Related free tools

DMARC Record Checker

Deep-dive into the DMARC record your score depends on, including reporting destinations and the RFC 9989 tree walk.

Open tool

SPF Record Checker

Expand nested SPF includes and verify the 10-DNS-lookup limit in detail.

Open tool

DKIM Record Checker

Inspect the DKIM public key and key size for a selector you know your provider uses.

Open tool

MTA-STS Checker

Validate the published MTA-STS policy and TLS-RPT reporting in isolation.

Open tool

Blacklist Checker

Run the IP or domain blocklist check on its own with per-provider evidence and delisting links.

Open tool

DNS Record Checker

Inspect every DNS record type for the domain, including A, AAAA, NS, MX and CAA.

Open tool

Frequently Asked Questions

What does the Domain Scanner check?

It audits everything a domain publishes about its email security: MX routing, SPF, DKIM (a selector you provide or a bounded scan of common selectors), DMARC including the RFC 9989 organizational-domain tree walk, MTA-STS and TLS-RPT transport security, BIMI, CAA, public DNSBL/RHSBL blocklist signals, and forward-confirmed reverse DNS for MX hosts. Every check runs against public DNS in a single pass, with duplicate queries deduplicated.

How is the 0–10 score calculated?

Nine weighted categories total 10 points: DMARC 2.0, SPF 1.5, DKIM 1.5, MX 1.0, MTA-STS & TLS-RPT 1.0, blocklists 1.5, BIMI 0.5, MX reverse DNS 0.5, CAA 0.5. A category earns its full weight when it passes, half weight on warnings, and zero when it fails. Checks that time out or cannot run are excluded from the denominator and lower the reported completeness instead of being counted against you.

Is the score a sender-reputation or deliverability score?

No. The score measures published DNS configuration only. It cannot see mailbox-provider reputation, complaint rates, engagement, sending behavior or content, and it never guarantees inbox placement. Public blocklist results are one signal among many, not a complete ISP reputation view.

Why is BIMI marked "not applicable" on some domains?

BIMI only works once DMARC enforces (p=quarantine or p=reject). Scoring a missing BIMI record on a domain with no DMARC enforcement would penalize the same root cause twice, so the scanner marks BIMI not applicable and excludes it from the denominator until DMARC is fixed — then it starts counting.

What happens when a check times out?

A timed-out, refused or failed check is reported as unknown and excluded from the score denominator. Unknown is never counted as a pass or as a failure — the completeness percentage tells you how much of the score is backed by definite evidence. Re-run the scan later if completeness looks low.

Does the scanner send email or connect to mail servers?

Never. The scanner only reads public DNS records and a few bounded HTTPS files (the MTA-STS policy and BIMI assets when published), all through SSRF-guarded fetches with strict size and time limits. It opens no SMTP connections, sends no test messages, and stores nothing you enter.

Increase Your Sales Right Now

Automate Sales Outreach & Get Booked!

Start Free Trial

(14 Day Free Trial, No CC Required)