Skip to content

Free instant domain check · no sign-up

Prove your email is yours.

Ten DNS checks in a few seconds: DMARC, SPF, DKIM and the rest, scored 0–100 with the exact records to publish. Stop spoofers sending as your domain, reach the inbox, and pass the sender rules Gmail, Yahoo and Outlook.com now enforce.

Paste a domain, a web address or an email address — we keep the domain part

yourdomain.co.uk · zone TXT · MX
_dmarc TXT "v=DMARC1; p=reject; rua=mailto:…@rua.mailproof"
@ TXT "v=spf1 include:spf.protection.outlook.com -all"
selector1._domainkey CNAME selector1-…_domainkey.onmicrosoft.com
! _mta-sts TXT — not published
@ MX 0 yourdomain-co-uk.mail.protection.outlook.com
Every finding comes with the record to publish, not just a red cross.

Why this matters now

Big inboxes require it

Gmail, Yahoo and Outlook.com require SPF, DKIM and a DMARC policy from bulk senders, and treat everyone else with more suspicion than they used to. Unauthenticated mail lands in spam or bounces.

Without DMARC anyone can be you

A domain with no policy can be spoofed in a phishing message to your customers, suppliers or staff, and receivers have no instruction to reject it.

It quietly breaks

A new CRM adds an SPF include, someone rotates a DKIM key, a provider changes its ranges. The record that passed last year fails today and nobody notices until invoices go missing.

Fixes are exact

Every problem MailProof finds comes with the precise record to publish, in copyable form, written for the person who has the DNS login.

What we check

Ten checks. One score. Plain English.

Weighted towards what protects you most: DMARC counts for 30 points, SPF and DKIM 20 each. BIMI is informational and never moves the score.

  • DMARC

    Tells receivers what to do with mail that fails authentication, and where to send you reports about who is sending as you.

  • SPF

    Lists the servers allowed to send for your domain. We walk every include and count the lookups against the limit of ten.

  • DKIM

    A cryptographic signature on each message proving it left your systems unaltered. We probe the selectors your providers use.

  • MX

    Where your inbound mail is delivered, whether those hosts resolve, and which provider is behind them.

  • MTA-STS

    Makes sending servers insist on encryption to your mail hosts, so mail to you cannot be downgraded in transit.

  • TLS-RPT

    Asks other servers to report when they could not deliver to you securely.

  • DNSSEC

    Signs your DNS so none of the records above can be forged on their way to a resolver.

  • Nameservers

    The servers everything else depends on. We check they resolve and that there is more than one.

  • Blocklists

    Whether your domain or mail server addresses appear on Spamhaus, SpamCop, Barracuda, SORBS, PSBL, SURBL or URIBL.

  • BIMI

    Your logo beside your messages in supporting inboxes, once DMARC is enforcing.

How it works

From domain to fix list in one page load

  1. Step 1

    Enter a domain

    Yours, a client's, a prospect's. No account, no email address, no waiting.

  2. Step 2

    We read the DNS

    Over DNS-over-HTTPS with DNSSEC validation, walking every SPF include, probing common DKIM selectors, fetching the MTA-STS policy and querying seven blocklists.

  3. Step 3

    Get the score and the records

    A grade, a one-line verdict, each finding explained, and the exact TXT records to publish. Copy, paste into your DNS, re-check.

For MSPs and agencies

Built for the people who look after fifty domains, not one

The free check is one domain, once. The platform is every client domain, continuously, in one place, with the evidence you need when a client asks why their invoices went to spam.

Clients as groups, one login for you
Add domains in bulk, group them by client, and see the whole estate ranked by score. Invite colleagues with the role they need.
Monitoring and change alerts
Every domain is re-scanned on a schedule. When an SPF record, DMARC policy, MX or DKIM key changes, you get an email saying what changed, from what, to what.
DMARC reports decoded
Point each client's rua= at us. Aggregate reports are unpacked, sources named by provider, and new senders raise an alert, so you can move to p=reject with confidence.
Send a test email, get a grade
Each domain gets a private test address. Send to it from the client's real systems and see SPF, DKIM and DMARC evaluated on a live message, plus headers, links and content checks.
Set-up guides per provider
Microsoft 365, Google Workspace, Mailchimp, SendGrid, Postmark, Mailgun, Amazon SES, HubSpot, Zoho and more: the SPF include, the DKIM selectors, and where to click.
Findings with history
Each problem carries first-seen and resolved dates across scans, so you can show a client what was fixed and when.

Check a domain now

It takes a few seconds and you keep the link to share with whoever holds the DNS login.