Enter a domain for a comprehensive email security audit. One scan covers mail routing, SPF, DKIM, DMARC, MTA-STS, BIMI, public blocklists and reverse DNS — and returns a transparent 0–10 security-configuration score with a prioritized fix list.
Enter a domain for a full email security audit: mail routing, SPF, DKIM, DMARC, MTA-STS, BIMI, public blocklists and reverse DNS.
We query public DNS and a few bounded HTTPS policy/asset files on your behalf. The domain you enter is used only to run the scan; results are not stored.
The scanner resolves A, AAAA, NS, MX and CAA once, then runs every protocol check through a shared cache — a DNS name is queried at most once per scan, keeping the whole audit under a documented query budget.
SPF (with nested includes and the 10-lookup limit), DKIM at your selector or a bounded common-selector scan, DMARC with the RFC 9989 tree walk, MTA-STS with TLS-RPT, and BIMI with its DMARC prerequisite.
Domain blocklists (RHSBL) and resolved-IP lists are checked against the reviewed public provider set, and MX hosts get forward-confirmed reverse DNS observations.
Each category earns its published weight; unknown results are excluded from the denominator and shown as completeness. Findings are merged and de-duplicated into a prioritized remediation plan with links to the dedicated checkers.
Deep-dive into the DMARC record your score depends on, including reporting destinations and the RFC 9989 tree walk.
Open toolInspect the DKIM public key and key size for a selector you know your provider uses.
Open toolRun the IP or domain blocklist check on its own with per-provider evidence and delisting links.
Open toolInspect every DNS record type for the domain, including A, AAAA, NS, MX and CAA.
Open toolIt audits everything a domain publishes about its email security: MX routing, SPF, DKIM (a selector you provide or a bounded scan of common selectors), DMARC including the RFC 9989 organizational-domain tree walk, MTA-STS and TLS-RPT transport security, BIMI, CAA, public DNSBL/RHSBL blocklist signals, and forward-confirmed reverse DNS for MX hosts. Every check runs against public DNS in a single pass, with duplicate queries deduplicated.
Nine weighted categories total 10 points: DMARC 2.0, SPF 1.5, DKIM 1.5, MX 1.0, MTA-STS & TLS-RPT 1.0, blocklists 1.5, BIMI 0.5, MX reverse DNS 0.5, CAA 0.5. A category earns its full weight when it passes, half weight on warnings, and zero when it fails. Checks that time out or cannot run are excluded from the denominator and lower the reported completeness instead of being counted against you.
No. The score measures published DNS configuration only. It cannot see mailbox-provider reputation, complaint rates, engagement, sending behavior or content, and it never guarantees inbox placement. Public blocklist results are one signal among many, not a complete ISP reputation view.
BIMI only works once DMARC enforces (p=quarantine or p=reject). Scoring a missing BIMI record on a domain with no DMARC enforcement would penalize the same root cause twice, so the scanner marks BIMI not applicable and excludes it from the denominator until DMARC is fixed — then it starts counting.
A timed-out, refused or failed check is reported as unknown and excluded from the score denominator. Unknown is never counted as a pass or as a failure — the completeness percentage tells you how much of the score is backed by definite evidence. Re-run the scan later if completeness looks low.
Never. The scanner only reads public DNS records and a few bounded HTTPS files (the MTA-STS policy and BIMI assets when published), all through SSRF-guarded fetches with strict size and time limits. It opens no SMTP connections, sends no test messages, and stores nothing you enter.
Automate Sales Outreach & Get Booked!
Start Free Trial(14 Day Free Trial, No CC Required)