Email and DNS toolkit limitationsResults are public-DNS observations, local parsers and bounded cryptographic checks—not proof of identity, delivery, reputation or compliance.
Message and DMARC inputs remain in the browser, but copying, forwarding or exporting can alter evidence. DKIM RSA-SHA256 verification depends on complete unmodified source and the currently published key; unsupported algorithms are labelled. DNSSEC uses public-resolver validation plus DS digest matching, while some TLSA selectors cannot be byte-matched in this runtime. No SMTP server is required or contacted. Monitoring stops when its page closes. Live delivery, mailbox acceptance, commercial reputation, inbox-placement and proprietary blacklist coverage are excluded.
Important: Do not rely on this result alone for purchasing, configuration, security, safety, compliance, contractual or fault-diagnosis decisions. Results can be incomplete, delayed, misleading or wrong. Verify important findings with the relevant provider, manufacturer documentation and an appropriate independent test or qualified professional.
Email and public DNS
Email & DNS Toolkit
Focused tools for authentication, published transport policy and public DNS. No SMTP server is required; message headers and DMARC files stay in your browser.
Tool directory
Choose a focused diagnostic
Each tool has its own URL, privacy controls, limitations and exportable results.Accuracy boundary
These passive checks require no SMTP server and report observable public-DNS, HTTPS-policy and message evidence—not guaranteed delivery, mailbox acceptance, identity, reputation or compliance. DNS caches, forwarding, message rewriting and source-policy limits can change results.