# Will your email reach the inbox? Check your domain's setup

> A free check of the DNS records Gmail, Yahoo and Microsoft look at before they accept your mail, including SPF, DKIM and DMARC. Every problem is explained in plain English and ranked, with the exact record to add. It runs in your browser.

By MailSetupCheck. Updated 7 October 2026. Canonical URL: https://mailsetupcheck.com/

> **Interactive checker.** On the HTML version of this page (https://mailsetupcheck.com/), enter a domain. Your browser asks Cloudflare's public DNS-over-HTTPS resolver (Google Public DNS as a fallback) for the domain's MX, SPF, DMARC, DKIM, MTA-STS, TLS-RPT and BIMI records, and the checker returns a fix list in three tiers: must fix to send to Gmail at volume, should fix, and nice to have, with the exact record to add where it can be worked out. MailSetupCheck has no server; the domain is never sent to it.

What it checks, in short:

- **MX**: present, null MX (RFC 7505), and the mail provider recognized from the host names.
- **SPF** (RFC 7208): exactly one v=spf1 record, valid syntax, every include and redirect followed, DNS-querying terms counted against the limit of 10 and empty lookups against 2, "+all", "?all", a missing "all", and "ptr".
- **DMARC** (RFC 9989, which replaced RFC 7489 in 2026): found at _dmarc.<domain> or by the DNS tree walk, every tag parsed, p=none explained, and an authorization record checked for report addresses at another organization (RFC 9990).
- **DKIM** (RFC 6376): your selector plus 34 common ones; key type and size (RFC 8301: at least 1024 bits, 2048 recommended). Not finding a key at these names does not prove DKIM is off.
- **MTA-STS** (RFC 8461), **TLS-RPT** (RFC 8460) and **BIMI** records.

DKIM selectors tried: `google` (Google Workspace (default)), `selector1` (Microsoft 365), `selector2` (Microsoft 365), `s1` (SendGrid), `s2` (SendGrid), `m1` (SendGrid (without automated security)), `k1` (Mailchimp (older setups)), `k2` (Mailchimp), `k3` (Mailchimp), `mte1` (Mailchimp Transactional (Mandrill)), `mte2` (Mailchimp Transactional (Mandrill)), `brevo1` (Brevo), `brevo2` (Brevo), `mail` (Brevo (older setups) and others), `km1` (Klaviyo (marketing)), `km2` (Klaviyo (marketing)), `kt1` (Klaviyo (transactional)), `kt2` (Klaviyo (transactional)), `ctct1` (Constant Contact), `ctct2` (Constant Contact), `mailjet` (Mailjet), `resend` (Resend), `zoho` (Zoho Mail (the example name in Zoho's guide; admins choose their own)), `fm1` (Fastmail), `fm2` (Fastmail), `fm3` (Fastmail), `protonmail` (Proton Mail), `protonmail2` (Proton Mail), `protonmail3` (Proton Mail), `sig1` (iCloud+ custom email domains), `x` (MXroute), `default` (cPanel and other hosting control panels), `cf2024-1` (Cloudflare Email Routing (signs forwarded mail)), `dkim` (Generic name some providers and admins use).

## What the checker looks at

| Record | Where it lives | What it does | What the checker tests |
|---|---|---|---|
| MX | Your domain | Names the servers that receive your mail | Present or not, null MX, which provider runs it |
| SPF | TXT record on your domain | Lists the servers allowed to send as you | Exactly one record, valid syntax, the 10-lookup limit, how it ends |
| DKIM | TXT or CNAME at *selector*._domainkey | Publishes the key that proves your mail was not forged | Key found, key size, test mode |
| DMARC | TXT record at _dmarc | Tells receivers what to do when SPF and DKIM fail, and where to send reports | Policy, reporting, subdomains, permission to send reports elsewhere |
| MTA-STS | TXT at _mta-sts, plus a policy file | Makes other servers use encrypted delivery when they send to you | Record valid, policy host exists |
| TLS-RPT | TXT at _smtp._tls | Asks for daily reports on failed encrypted deliveries | Record valid |
| BIMI | TXT at default._bimi | Shows your logo in supporting inboxes | Record valid, DMARC at enforcement, certificate |

The [methodology](/methodology/) lists every rule, the DKIM selectors the checker tries, and the standards each rule comes from.

## What a DNS check cannot see

DNS is public; your messages are not. Several of the [Gmail, Yahoo and Microsoft sender rules](/gmail-yahoo-bulk-sender-requirements/) depend on how each message is sent, so no DNS check can confirm them:

- **Alignment.** DMARC passes only when the domain in your From address matches the domain that SPF or DKIM checked. That depends on your sending service's settings. To see it, send a message to a Gmail address, open it, choose "Show original", and look for `dmarc=pass` in the `Authentication-Results` header.
- **Your sending servers.** Gmail and Yahoo also require reverse DNS (PTR) records and encrypted connections from the servers that send your mail. Google Workspace, Microsoft 365 and the large sending services handle both.
- **Spam rate.** Gmail asks for under 0.1% and acts at 0.3%. [Google Postmaster Tools](https://postmaster.google.com/) shows your rate once you send enough mail to Gmail users.
- **Unsubscribe headers.** Marketing mail to Gmail and Yahoo users needs one-click unsubscribe, which is a header in each message, not a DNS record.
- **DKIM keys at names nobody can guess.** DKIM keys sit under a name the sender picks. The checker tries the common ones; if yours is unusual, enter it under Options. The `s=` value in the `DKIM-Signature` header of a message you sent is your selector.

## Guides

- [Gmail and Yahoo bulk sender requirements explained](/gmail-yahoo-bulk-sender-requirements/): what each mailbox provider requires, who counts as a bulk sender, and what happens when you miss.
- [SPF too many DNS lookups: how to fix](/spf-too-many-dns-lookups/): why the limit is 10, how many lookups common services cost (measured), and the safe fixes.
- [DMARC p=none to reject: a safe rollout](/dmarc-p-none-to-reject/): how to move from monitoring to protection without blocking your own mail.
- [Cold email that stays legal](/cold-email-can-spam/): CAN-SPAM in plain English, with the mailbox providers' rules on top.
- [Cold email cost calculator](/cold-email-cost-calculator/): inboxes, domains, warmup time and monthly cost for a sending target.

## How the checker works

Your browser asks a public DNS resolver for each record: Cloudflare's DNS-over-HTTPS service, and Google Public DNS if Cloudflare does not answer. MailSetupCheck has no server in that path, so the domain you check is never sent to this site ([privacy](/privacy/)). The rules that turn records into fixes are plain JavaScript, tested against recorded DNS answers before every deploy, and each one links to the standard or mailbox-provider page it comes from.
