Free email security tools
Checkers, generators and analysers for DMARC, SPF, DKIM, BIMI, MTA-STS, DNS and email threats. Free, no sign-up.
A free toolkit for diagnosing email authentication and DNS. No sign-up, no limits, no card. Every tool runs the same checks our engine uses to take domains to enforced p=reject, so the results reflect what a receiving mail server actually evaluates. When you are ready to fix what you find, we can do it for you.
There are more than forty tools below, grouped by job. Some look up a live record and tell you in plain English whether it is valid. Some generate a correct record from a short form so you do not have to memorise the syntax. Others analyse a whole domain, an SMTP path or a suspicious message and score what they find. Use the checkers to see where you stand, the generators to draft the fix, and the analysers to understand the risk. Each tool links to the relevant guide if you want the background as well as the result.
DMARC
DMARC is the policy that ties SPF and DKIM back to the address your recipient actually sees, then tells receivers what to do with mail that fails. Start with the DMARC Checker to read your current record and policy, use the Generator or Setup Wizard to draft a safe rollout from p=none toward p=reject, and feed a real aggregate (RUA) report into the Report Analyser to see exactly which sources are passing and which are being spoofed. Use these before you tighten a policy, never after, because moving to enforcement blind is how legitimate mail gets blocked.
Look up and validate a domain's DMARC record and policy.
DMARC GeneratorBuild a valid DMARC record from a simple form.
DMARC Report AnalyserRead a DMARC aggregate (RUA) report in plain English.
DMARC AnalyserFull DMARC, SPF and DKIM analysis with a readiness score.
Domain AnalyserOne scan of every email-authentication record on a domain.
Bulk Domain ScannerScan a whole list of domains at once for DMARC spoofability.
DMARC Setup WizardBuild a safe, staged DMARC rollout plan from p=none to p=reject.
Email Deliverability ScoreScore a domain's email authentication out of 100 with a shareable badge.
Spoofable Status BadgeGenerate an embeddable badge that shows your domain's live DMARC status.
SPF
SPF lists which servers are allowed to send for your domain, and it breaks more quietly than any other record. The hard limit of ten DNS lookups counts nested includes you cannot see, so a record that looks valid can still return permerror and fail every message. The SPF Checker resolves your record the way a receiver does and counts every lookup, including the hidden ones. The SPF Generator builds a clean record from your list of senders. Run the checker whenever you add or remove a mail provider.
DKIM
DKIM signs your mail with a private key and publishes the matching public key in DNS under a selector, so authentication travels with the message and survives forwarding where SPF does not. The DKIM Checker looks up a public key by selector and confirms it is valid and the right length. The DKIM Generator creates a key pair and the DNS record in your browser, so the private key never leaves your machine. Use the checker to confirm every sending platform has a working selector before you rely on DKIM for DMARC alignment.
BIMI
BIMI puts your verified logo next to your name in supporting inboxes, but only once DMARC is at enforcement and your logo meets a strict SVG profile. These tools cover the whole chain. The BIMI & VMC Checker tells you whether your domain is actually eligible end to end: enforcement, record, logo and certificate. The Generator builds the record, the SVG Converter and Logo Validator check your artwork against the Tiny PS profile, and the Simulator and CMC Simulator preview how the mark renders. Use the eligibility checker first; the logo work is wasted if DMARC is not yet enforced.
Check a domain's BIMI record, logo and VMC.
BIMI GeneratorCreate a BIMI record for your logo and VMC.
BIMI SVG Logo ConverterCheck and prepare an SVG for the BIMI Tiny PS profile.
BIMI SimulatorPreview how your logo looks in supporting inboxes.
CMC SimulatorPreview a Common Mark Certificate logo in the inbox.
BIMI Logo ValidatorValidate an SVG logo against the BIMI specification.
BIMI & VMC CheckerEnd-to-end BIMI readiness: DMARC enforcement, record, logo and VMC.
MTA-STS & TLS-RPT
These records protect mail in transit. MTA-STS, when set to enforce, tells sending servers to refuse delivery to your domain unless the connection is encrypted with a valid certificate, which closes the downgrade attacks that plain SMTP allows. TLS-RPT asks other providers to report TLS failures back to you so you can spot a problem early. DANE does the same job through DNSSEC-signed TLSA records. The MTA-STS Checker validates both the DNS record and the hosted policy file (a common point of failure), while the TLS-RPT and DANE checkers confirm the reporting and certificate-binding records resolve.
Security & threat analysis
Authentication records are the cause; fraud and poor deliverability are the effects these tools measure. The Spoofing Risk Calculator estimates your exposure to spoofed-invoice fraud, and the Lookalike Domain Checker finds registered variations attackers use to impersonate you. When a suspicious message lands, the Email Header Analyser and Phishing Email Checker trace its path and flag what is wrong, while the Phishing URL Checker scores a link. On the delivery side, the Blacklist Checker, SMTP Test and Fake Email Address Checker tell you whether your mail can reach the inbox at all.
Estimate your exposure to spoofed-invoice and email fraud.
Lookalike Domain CheckerFind registered lookalike variations of your domain.
Phishing URL CheckerScore a URL for common phishing red flags.
Blacklist CheckerCheck a domain or IP against email blacklists.
Email Header AnalyserParse raw email headers and trace the delivery path.
SMTP TestResolve a domain's mail servers and probe SMTP.
Fake Email Address CheckerCheck whether an email address looks deliverable.
Phishing Email CheckerAnalyse a suspicious email's headers and content.
DNS tools
Every email-authentication record lives in DNS, so when something looks wrong the cause is often one layer down. These general-purpose lookups let you check the foundations directly. Use the DNS Record Checker, TXT Record Checker and MX Record Checker to confirm a record actually exists and resolves; the DNS Propagation Checker to see whether a change has reached resolvers worldwide; and DNSSEC, CAA, PTR and FCrDNS checkers to verify the security and reverse-DNS settings that mail receivers also weigh. The Record Splitter chunks a long TXT value into 255-character pieces so a long DKIM or flattened SPF record publishes cleanly.
Look up any DNS record type for a host.
TXT Record CheckerLook up the TXT records on a host name.
PTR Record CheckerReverse-DNS lookup for an IPv4 address.
Reverse DNS (FCrDNS) CheckerCheck forward-confirmed reverse DNS (FCrDNS) for a mail IP or domain.
WHOIS Domain LookupRegistration details for a domain via RDAP.
DNSSEC CheckerCheck whether a domain is signed with DNSSEC.
CAA CheckerLook up Certificate Authority Authorization records.
MX Record CheckerLook up the mail servers for a domain.
DNS Record SplitterSplit a long TXT value into 255-character chunks.
WHOIS IP LookupOwnership and allocation details for an IP address.
DNS Propagation CheckerCompare a DNS record across global resolvers.
Why these tools are free, and why you can trust the answers
The honest version: the tools are free because they are how most people meet us. You arrive with a question about one record, you get a real answer, and if the answer is "your domain can be spoofed," you know where to find the people who fix that for a living.
Same engine as the paid product
Every checker runs the exact resolution and validation logic our platform uses to take paying customers to enforced p=reject. There is no watered-down free tier. The lookup count, the alignment result and the readiness score are the same numbers we act on internally.
We resolve, not just parse
Many free checkers only read the text of a record and call it valid. Ours resolve records the way a receiving mail server does, expanding nested SPF includes, following selectors and fetching hosted policy files, so they catch the failures a syntax check misses.
No sign-up, no catch
You do not need an account, a card or an email address to run any tool on this page. Key-generation tools run in your browser, so private keys never reach our servers. Use them as often as you like, for as many domains as you like.
From a free check to done-for-you enforcement
The tools tell you the truth about your domain. Acting on that truth is where most teams stall, because the work is fiddly, easy to get wrong, and risky to do live. That is the gap we close.
1. Check and see the gaps
Run a tool, or a full domain scan, and find out whether your domain can be spoofed today, whether SPF is over the lookup limit, and whether DMARC is at enforcement or just observing.
Scan a domain2. We host and align the records
Hand the records to us. We host DMARC, SPF, DKIM, MTA-STS and BIMI behind delegated DNS, auto-flatten SPF so it never trips the limit, and confirm every legitimate sender passes before anything tightens.
3. We take you to p=reject
We move your policy from p=none through quarantine to enforced p=reject in safe stages, watching aggregate reports the whole way, so spoofing stops without a single legitimate message being lost.
How enforcement worksFrequently asked questions
Do I need to create an account to use the tools?
No. Every tool on this page runs without a sign-up, a card or an email address. You only create an account if you decide to have us host and manage your records.
Are the free tools as accurate as the paid product?
Yes. They run the same resolution and validation engine. The difference is not accuracy, it is that the platform also acts on the results: it hosts your records, flattens SPF automatically, ingests your DMARC reports and walks you to enforcement. The tools tell you what is wrong; the product fixes and maintains it.
Is it safe to generate DKIM or BIMI keys here?
Yes. The key-generation tools run entirely in your browser. The private key is created on your device and never sent to us, so you can copy the public record into DNS and keep the private key yourself.
Why does an SPF record pass other checkers but fail yours?
Most free checkers only read the text of your record. Ours resolves it the way a receiving mail server does and counts every DNS lookup, including the nested includes hidden inside your providers' records. A record can be syntactically perfect and still return permerror because the hidden lookups push it over the limit of ten.
Which tool should I start with?
Run the Domain Analyser or a free scan for a single picture of every record at once. From there, drill into the SPF, DKIM or DMARC tools for the specific record you need to fix.
Can I check more than one domain at a time?
Yes. The Bulk Domain Scanner takes a list of domains and reports which of them can be spoofed, which is useful for agencies, acquisitions or auditing a portfolio.