Principles

  1. Standards and providers' own pages, nothing else. Every rule cites an RFC or a mailbox provider's published requirement. Every price links to the vendor's own pricing page with the date it was read.
  2. Say what cannot be known. DNS shows what a domain publishes, not how its mail is actually sent. The checker says so wherever it matters, and never reports a guess as a finding.
  3. Unknown stays unknown. A failed lookup becomes "could not check", never "missing". A price the vendor does not publish shows as "Check vendor", never as zero.
  4. Tested before every deploy. The rules are a plain JavaScript module tested against recorded DNS answers (no network in the tests), including real records copied from live domains.

How a check runs

  1. Your browser normalizes what you typed (a URL or an email address becomes a bare domain; "www." is dropped; international names become their ASCII form).
  2. It asks Cloudflare's public DNS-over-HTTPS service (cloudflare-dns.com) each question, and Google Public DNS (dns.google) if Cloudflare fails or answers SERVFAIL. Requests are sent without cookies or a referrer. MailSetupCheck has no server in this path.
  3. Answers are cached for the length of the check, and the check stops after 150 distinct questions so that an enormous SPF tree cannot run forever. A typical domain needs 40 to 50.
  4. The results are turned into findings by fixed rules, below, and sorted into three tiers.

The rules

MX

SPF (RFC 7208)

DMARC (RFC 9989, which replaced RFC 7489 in May 2026)

DKIM (RFC 6376)

MTA-STS, TLS-RPT and BIMI

The tiers

What the checker cannot see

Alignment of real messages, the reverse DNS and TLS of your sending servers, spam rate, unsubscribe headers, message content, and DKIM keys at selectors it did not try. The home page explains how to check each one yourself.

DKIM selectors tried

A selector is a name chosen by the provider or the domain's admin, so this list can only cover conventions. "dns:" means the convention was confirmed by looking up the provider's own domain on 7 October 2026. Amazon SES, HubSpot and Postmark use account-specific selectors that cannot be guessed.

Selector Usually used by Source
google Google Workspace (default) provider documentation
selector1 Microsoft 365 provider documentation
selector2 Microsoft 365 provider documentation
s1 SendGrid provider documentation
s2 SendGrid provider documentation
m1 SendGrid (without automated security) dns:m1._domainkey.sendgrid.com
k1 Mailchimp (older setups) dns:k1._domainkey.mailchimp.com
k2 Mailchimp dns:k2._domainkey.mailchimp.com
k3 Mailchimp dns:k3._domainkey.mailchimp.com
mte1 Mailchimp Transactional (Mandrill) dns:mte1._domainkey.mailchimp.com
mte2 Mailchimp Transactional (Mandrill) dns:mte1._domainkey.mailchimp.com
brevo1 Brevo provider documentation
brevo2 Brevo provider documentation
mail Brevo (older setups) and others dns:mail._domainkey.brevo.com
km1 Klaviyo (marketing) provider documentation
km2 Klaviyo (marketing) provider documentation
kt1 Klaviyo (transactional) provider documentation
kt2 Klaviyo (transactional) provider documentation
ctct1 Constant Contact provider documentation
ctct2 Constant Contact provider documentation
mailjet Mailjet dns:mailjet._domainkey.mailjet.com
resend Resend dns:resend._domainkey.resend.com
zoho Zoho Mail (the example name in Zoho's guide; admins choose their own) provider documentation
fm1 Fastmail provider documentation
fm2 Fastmail provider documentation
fm3 Fastmail provider documentation
protonmail Proton Mail dns:protonmail._domainkey.proton.me
protonmail2 Proton Mail dns:protonmail2._domainkey.proton.me
protonmail3 Proton Mail dns:protonmail._domainkey.proton.me
sig1 iCloud+ custom email domains provider documentation
x MXroute provider documentation
default cPanel and other hosting control panels dns:default._domainkey.cpanel.net
cf2024-1 Cloudflare Email Routing (signs forwarded mail) provider documentation
dkim Generic name some providers and admins use generic convention

Mail providers recognized

Provider Kind MX host names ending in SPF include suggested
Google Workspace mailbox google.com, googlemail.com _spf.google.com
Microsoft 365 mailbox mail.protection.outlook.com, mx.microsoft spf.protection.outlook.com
Zoho Mail mailbox zoho.com, zoho.eu, zoho.in, zoho.com.au, zoho.jp, zoho.sa, zohocloud.ca zohomail.com
Fastmail mailbox messagingengine.com spf.messagingengine.com
Proton Mail mailbox protonmail.ch _spf.protonmail.ch
iCloud+ custom email domain mailbox mail.icloud.com icloud.com
MXroute mailbox mxrouting.net none (generic advice)
Yahoo mailbox yahoodns.net none (generic advice)
GoDaddy email mailbox secureserver.net none (generic advice)
Namecheap Private Email mailbox privateemail.com none (generic advice)
Rackspace Email mailbox emailsrvr.com none (generic advice)
Titan Email mailbox titan.email none (generic advice)
IONOS mailbox ionos.com, ionos.de, ionos.co.uk, kundenserver.de none (generic advice)
Migadu mailbox migadu.com none (generic advice)
Amazon WorkMail or SES inbound mailbox amazonaws.com none (generic advice)
Mimecast gateway mimecast.com, mimecast.co.za none (generic advice)
Proofpoint gateway pphosted.com, ppe-hosted.com none (generic advice)
Barracuda gateway barracudanetworks.com none (generic advice)
Cisco Secure Email gateway iphmx.com none (generic advice)
Cloudflare Email Routing forwarding mx.cloudflare.net _spf.mx.cloudflare.net
ImprovMX forwarding improvmx.com none (generic advice)

An SPF include is suggested only where the provider's own setup page states it. A "gateway" filters mail before it reaches your real mailbox provider; "forwarding" services receive mail but cannot send it for you.

The cold email cost calculator

Conflicts of interest

MailSetupCheck may earn referral commissions from some vendors it mentions; the affiliate disclosure lists them. Commissions do not change the rules, the tiers, or the order of the calculator's table, which is sorted by price.

Also available as Markdown.