Check your domain's email setup

Runs in your browser. Lookups go straight from your browser to Cloudflare's public DNS resolver (Google Public DNS if Cloudflare fails). MailSetupCheck has no server and never sees the domain you check.

The part after the @ in your email address. You can paste a website address or an email address too.

Options: DKIM selector and DMARC report address

Where to find your selector: open a message you sent, view the original or raw message, and read s= in the DKIM-Signature line. The checker also tries 33 common selectors.

Used only to fill in the DMARC record the checker suggests. It is not looked up or sent anywhere.

What the checker looks at

Record Where it lives What it does What the checker tests
MX Your domain Names the servers that receive your mail Present or not, null MX, which provider runs it
SPF TXT record on your domain Lists the servers allowed to send as you Exactly one record, valid syntax, the 10-lookup limit, how it ends
DKIM TXT or CNAME at selector._domainkey Publishes the key that proves your mail was not forged Key found, key size, test mode
DMARC TXT record at _dmarc Tells receivers what to do when SPF and DKIM fail, and where to send reports Policy, reporting, subdomains, permission to send reports elsewhere
MTA-STS TXT at _mta-sts, plus a policy file Makes other servers use encrypted delivery when they send to you Record valid, policy host exists
TLS-RPT TXT at _smtp._tls Asks for daily reports on failed encrypted deliveries Record valid
BIMI TXT at default._bimi Shows your logo in supporting inboxes Record valid, DMARC at enforcement, certificate

The methodology lists every rule, the DKIM selectors the checker tries, and the standards each rule comes from.

What a DNS check cannot see

DNS is public; your messages are not. Several of the Gmail, Yahoo and Microsoft sender rules depend on how each message is sent, so no DNS check can confirm them:

Guides

How the checker works

Your browser asks a public DNS resolver for each record: Cloudflare's DNS-over-HTTPS service, and Google Public DNS if Cloudflare does not answer. MailSetupCheck has no server in that path, so the domain you check is never sent to this site (privacy). The rules that turn records into fixes are plain JavaScript, tested against recorded DNS answers before every deploy, and each one links to the standard or mailbox-provider page it comes from.

More free tools and guides

  • Cold email cost calculator

    Inboxes, domains, warmup weeks and monthly cost for a daily sending target, with sourced prices for Google Workspace, Microsoft 365, Instantly, Smartlead, lemlist and three verification services.

  • Cold email that stays legal

    CAN-SPAM's seven requirements in plain English, the $53,088 per-email penalty, and the mailbox-provider rules on top.

  • DMARC rollout, p=none to reject

    Monitoring to protection without blocking your own mail, updated for RFC 9989 (pct removed, t=y added).

  • Gmail and Yahoo sender rules

    Who counts as a bulk sender, what Gmail, Yahoo and Outlook.com require, and what happens when you miss, from each provider's own pages.

  • SPF too many DNS lookups

    Why the limit is 10, what each common service costs (measured from live DNS), and the fixes in order of safety.

Also available as Markdown.