Domain & email reputation check: SPF, DKIM, DMARC, blacklists
See in 15 seconds why email from your domain lands in spam. For every problem you get a ready DNS record tailored to your mail provider.
Open any email sent from your domain, view the original message (headers) and find the DKIM-Signature line. The selector follows s=: in s=google; it is google.
We only read public DNS records and public blacklists. We send no email and never log in to any mailbox.
- Mail servers (MX)
- SPF
- DKIM
- DMARC
- Blacklists
- Domain age
What the result looks like
company.com
- No DMARC: receivers don't know what to do with forged mail
- SPF is missing include:_spf.google.com
- Mail server IP has no PTR record
Example for a made-up domain. Your result appears here in 10–15 seconds.
Why your emails may land in spam
Gmail, Yahoo and Outlook requirements
You also need one-click unsubscribe (List-Unsubscribe) and a spam complaint rate under 0.3%. Those are visible only in the providers' dashboards: Google Postmaster Tools ↗ Yahoo Sender Hub ↗ Microsoft SNDS ↗
Section by section
Full PDF report by email
Every section, the records we found and the ready fixes in one document. Easy to forward to your admin or contractor.
We'll set up SPF, DKIM and DMARC and get your domain off blacklists
A YuSMP engineer configures email authentication for your provider (Google Workspace, Microsoft 365, Zoho and others), moves DMARC from monitoring to enforcement step by step and files delisting requests.
- SPF without extra DNS lookups or PermError
- 2048-bit DKIM for every service that sends as you
- DMARC from p=none to p=reject, with report analysis
- Blacklist removal and PTR checks
Need link authority rather than email? Try the Domain Rating tool: it scores your backlink profile.
What the check covers
Mailbox providers decide where a message goes based on your domain's DNS records and the reputation of the addresses it came from. We check everything that is visible from the outside.
SPF
Which servers may send mail for your domain. We check syntax, the 10-DNS-lookup limit and the -all / ~all ending.
DKIM
The cryptographic signature on your messages. We look up the key by common selectors and yours, and check its length: 1024 bits is weak, 2048 is the norm.
DMARC
The policy for forged mail and the reports about it. We check p=, rua reports, testing mode and the new DMARCbis tags.
MX and PTR
Your mail servers, their IPs and reverse records. Without PTR many providers reject mail before they even look at the content.
Blacklists
The IPs of your mail servers, website and SPF against SpamCop, PSBL, Mailspike and UCEPROTECT. Every listing comes with a delisting link.
Domain age
Registration and expiry dates. Providers are wary of domains under a month old, and an expired domain stops receiving mail.
FAQ
Why do emails from my domain go to spam?
Usually for one of three reasons: there is no DMARC or it is set to p=none, SPF does not list the service you send through, or DKIM signing is not set up. Less often the server IP is on a blacklist. The check shows which one applies to you and gives a ready record to fix it.
What are SPF, DKIM and DMARC in plain words?
SPF is the list of servers allowed to send mail for your domain. DKIM is a signature on each message that cannot be forged. DMARC tells receivers what to do when SPF and DKIM fail, and where to send reports.
The tool says DKIM is not found, but I have it
A DKIM selector can be any word, so nobody can guess them all. We try 24 common ones. Find yours in the DKIM-Signature header (the s= parameter) and enter it in the DKIM selector field.
How do I get off a blacklist?
First remove the cause: a compromised mailbox, an open relay, bulk mail without consent. Then file a request using the link next to the listing. SpamCop delists automatically about a day after the complaints stop.
How is this different from Domain Rating?
Domain Rating scores your site's backlink authority for SEO. This tool checks email: whether mailbox providers trust mail from your domain.
Do you store my data?
The domain result is cached for 10 minutes so a repeat request answers instantly. That is public DNS data. Your email address reaches us only if you ask for the report or send a request.