Composite SPF / DKIM / DMARC / MX check with a single 0-100 score.
A composite SPF / DKIM / DMARC / MX check rolled into a single 0-100 score. The same engine that powers the in-app Domain Health add-on, exposed here without an account — one lookup, the full picture.
Email deliverability rests on four DNS-level signals: SPF authorises your sending IPs, DKIM cryptographically signs your mail, DMARC tells receivers what to do when the first two fail to align, and MX records prove your domain can receive mail at all. Checking these one at a time is fine when you know what you're looking for, but most deliverability problems come from the gaps between them — a perfect SPF record means little if DMARC is still sitting at p=none, and DKIM signing is invisible to DMARC unless it aligns. This tool runs all four checks at once and weights them into a single 0-100 health score.
This is the right place to start. Before you wire up an ESP, before your first campaign, and any time you inherit a domain whose history you don't know, run the composite check to get the headline number and the per-record breakdown. The score tells you how much trust mailbox providers will extend to your mail; the breakdown tells you exactly which of the four pillars to fix first. From there you can jump into the dedicated SPF, DKIM, or DMARC checker to drill in.
A high score is a snapshot, not a guarantee. DNS records change, ESPs rotate keys, and a teammate publishing a second SPF record can silently break authentication overnight. Treat this check as the entry point to a repeatable habit: run it during setup, again as pre-send QA before anything important, and on a schedule for ongoing monitoring. The in-app Domain Health add-on automates exactly that across every domain you send from.
It's a weighted roll-up of the four checks — SPF, DKIM, DMARC, and MX. Present, valid, and appropriately strict records earn full marks; missing or weak ones (a DMARC policy stuck at none, a soft-fail SPF, no DKIM key) cost points. It's the same scoring the in-app Domain Health add-on uses.
Roughly: 85+ is a strong, enforced posture; 65-84 is functional but has room to tighten (often DMARC not yet at reject); 40-64 means a pillar is missing or weak; below 40 means authentication is largely absent and your mail is at real risk of spam or rejection.
MX records prove your domain can actually receive mail, which matters for two-way deliverability, bounce handling, and DMARC reporting. A domain with great SPF/DKIM/DMARC but no MX is configured to send but can't receive — usually a sign the setup is incomplete.
Follow the breakdown. If SPF or DKIM is missing, fix authentication first — DMARC can't enforce without at least one of them aligning. If both pass but DMARC is at none, your next move is to ramp DMARC toward enforcement.
No. This checks your DNS authentication posture, which is the foundation of deliverability. Whether a specific message lands in the inbox also depends on content and reputation — for that, use the email spam checker, or run a real seed-list placement test inside SieveGuard.
At domain setup, as pre-send QA before important campaigns, and on a recurring schedule for monitoring. DNS drifts; a clean score today doesn't guarantee a clean score after the next stack change.
SieveGuard's Domain Health add-on runs this exact composite check on every email address you screen, surfaces the score as a per-record badge, and alerts you the moment a record changes. Free during your trial.