Email and DNS toolkit limitationsResults are public-DNS observations, local parsers and bounded cryptographic checks—not proof of identity, delivery, reputation or compliance.
Message and DMARC inputs remain in the browser, but copying, forwarding or exporting can alter evidence. DKIM RSA-SHA256 verification depends on complete unmodified source and the currently published key; unsupported algorithms are labelled. DNSSEC uses public-resolver validation plus DS digest matching, while some TLSA selectors cannot be byte-matched in this runtime. No SMTP server is required or contacted. Monitoring stops when its page closes. Live delivery, mailbox acceptance, commercial reputation, inbox-placement and proprietary blacklist coverage are excluded.
Important: Do not rely on this result alone for purchasing, configuration, security, safety, compliance, contractual or fault-diagnosis decisions. Results can be incomplete, delayed, misleading or wrong. Verify important findings with the relevant provider, manufacturer documentation and an appropriate independent test or qualified professional.
RFC-aware sender policy
SPF evaluator
Validate a domain’s SPF policy and include or redirect branches. Add a sender IP when you also need a MAIL FROM or HELO authorization result.
Enter a public domain to begin.
Change-control warning: suggested corrections are starting points, not authoritative records. Inventory every sending service and verify a real message's Authentication-Results before changing production DNS. No SMTP server connection is required by this tool.