Free instant domain check · no sign-up
Prove your email is yours.
Ten DNS checks in a few seconds: DMARC, SPF, DKIM and the rest, scored 0–100 with the exact records to publish. Stop spoofers sending as your domain, reach the inbox, and pass the sender rules Gmail, Yahoo and Outlook.com now enforce.
Why this matters now
Big inboxes require it
Gmail, Yahoo and Outlook.com require SPF, DKIM and a DMARC policy from bulk senders, and treat everyone else with more suspicion than they used to. Unauthenticated mail lands in spam or bounces.
Without DMARC anyone can be you
A domain with no policy can be spoofed in a phishing message to your customers, suppliers or staff, and receivers have no instruction to reject it.
It quietly breaks
A new CRM adds an SPF include, someone rotates a DKIM key, a provider changes its ranges. The record that passed last year fails today and nobody notices until invoices go missing.
Fixes are exact
Every problem MailProof finds comes with the precise record to publish, in copyable form, written for the person who has the DNS login.
What we check
Ten checks. One score. Plain English.
Weighted towards what protects you most: DMARC counts for 30 points, SPF and DKIM 20 each. BIMI is informational and never moves the score.
-
DMARC
Tells receivers what to do with mail that fails authentication, and where to send you reports about who is sending as you.
-
SPF
Lists the servers allowed to send for your domain. We walk every include and count the lookups against the limit of ten.
-
DKIM
A cryptographic signature on each message proving it left your systems unaltered. We probe the selectors your providers use.
-
MX
Where your inbound mail is delivered, whether those hosts resolve, and which provider is behind them.
-
MTA-STS
Makes sending servers insist on encryption to your mail hosts, so mail to you cannot be downgraded in transit.
-
TLS-RPT
Asks other servers to report when they could not deliver to you securely.
-
DNSSEC
Signs your DNS so none of the records above can be forged on their way to a resolver.
-
Nameservers
The servers everything else depends on. We check they resolve and that there is more than one.
-
Blocklists
Whether your domain or mail server addresses appear on Spamhaus, SpamCop, Barracuda, SORBS, PSBL, SURBL or URIBL.
-
BIMI
Your logo beside your messages in supporting inboxes, once DMARC is enforcing.
How it works
From domain to fix list in one page load
-
Step 1
Enter a domain
Yours, a client's, a prospect's. No account, no email address, no waiting.
-
Step 2
We read the DNS
Over DNS-over-HTTPS with DNSSEC validation, walking every SPF include, probing common DKIM selectors, fetching the MTA-STS policy and querying seven blocklists.
-
Step 3
Get the score and the records
A grade, a one-line verdict, each finding explained, and the exact TXT records to publish. Copy, paste into your DNS, re-check.
For MSPs and agencies
Built for the people who look after fifty domains, not one
The free check is one domain, once. The platform is every client domain, continuously, in one place, with the evidence you need when a client asks why their invoices went to spam.
- Clients as groups, one login for you
- Add domains in bulk, group them by client, and see the whole estate ranked by score. Invite colleagues with the role they need.
- Monitoring and change alerts
- Every domain is re-scanned on a schedule. When an SPF record, DMARC policy, MX or DKIM key changes, you get an email saying what changed, from what, to what.
- DMARC reports decoded
- Point each client's
rua=at us. Aggregate reports are unpacked, sources named by provider, and new senders raise an alert, so you can move top=rejectwith confidence. - Send a test email, get a grade
- Each domain gets a private test address. Send to it from the client's real systems and see SPF, DKIM and DMARC evaluated on a live message, plus headers, links and content checks.
- Set-up guides per provider
- Microsoft 365, Google Workspace, Mailchimp, SendGrid, Postmark, Mailgun, Amazon SES, HubSpot, Zoho and more: the SPF include, the DKIM selectors, and where to click.
- Findings with history
- Each problem carries first-seen and resolved dates across scans, so you can show a client what was fixed and when.
Check a domain now
It takes a few seconds and you keep the link to share with whoever holds the DNS login.