Swift·Cap

DNS and email / DNS and email deliverability

DNS and email deliverability

Two concrete risks are settled in your DNS zone: your legitimate email landing in junk, and your domain being used to send fake messages to your customers. We read your public records and tell you which of the two threatens you.

DNS lookups only: no email is sent or received, no server is contacted beyond a resolution query. Test only a domain you own or are authorised to test.

Passive DNS lookups only — no email sent, no intrusion. By running the check you confirm you own the domain or are authorised to test it.

What we check

  • SPF

    Which servers are allowed to send on your behalf? We check presence, uniqueness, the final policy (`-all`, `~all`, `?all`, `+all`) and the budget of ten DNS lookups.

  • DMARC

    What do you ask receiving servers to do when a message fails the checks? We read the published policy and the address that collects the reports.

  • DKIM

    We query the most common selectors. A key found is proof; an absence on those selectors is not, and the report says so explicitly.

  • MX and name servers

    Can your domain receive email, and are your name servers numerous and spread out enough to survive an outage?

The results reflect what the DNS servers publish at the moment of the query. A recent change to your zone can take several hours to propagate before it appears here.

Also check the website's security