Create a free account to unlock more allowance, saved reports, and trial API access.
Use the Email Security Check tool to review the DNS records that protect your domain email from spoofing, phishing, and deliverability problems. This tool helps you check SPF, DKIM, DMARC, MX, and related email authentication settings for a domain.
If your emails are going to spam, failing authentication, being rejected, or your domain is at risk of spoofing, checking email security records is one of the most important steps in troubleshooting.
What Is Email Security Check?
Email Security Check is a DNS-based analysis of the records that help verify whether email sent from a domain is legitimate. Modern mail systems use SPF, DKIM, and DMARC to evaluate sender identity and reduce spoofing.
These records are published in DNS and checked by receiving mail servers. If they are missing, incorrect, or misaligned, email messages may land in spam, fail authentication, or be rejected.
Why Email Security Records Matter
Email is one of the most common attack surfaces for businesses. Attackers may try to send fake emails that appear to come from your domain. Proper email authentication makes spoofing harder and improves trust with mail providers.
Email security records help with:
- Reducing domain spoofing and phishing risk.
- Improving email deliverability.
- Helping Gmail, Outlook, Yahoo, and other providers validate your messages.
- Protecting brand reputation.
- Supporting business email and transactional email reliability.
How to Use the Email Security Check Tool
Using the IPMYP Email Security Check tool is simple.
- Enter a domain name, such as
example.com. - Run the email security check.
- IPMYP reviews the domain’s email-related DNS records.
- Check whether SPF, DKIM, DMARC, and MX records are present and configured correctly.
- Use the results to identify missing, weak, or conflicting email DNS settings.
For a full domain diagnostic review, use the main online network tools hub to check DNS, WHOIS, SSL, Ping, Traceroute, and related tools.
What Does an Email Security Report Show?
An email security report may include several key DNS and authentication checks.
- MX Records: Mail servers responsible for receiving email.
- SPF Record: Servers allowed to send email for the domain.
- DKIM Records: Public keys used to verify signed emails.
- DMARC Record: Policy for handling emails that fail SPF or DKIM.
- Record Warnings: Missing, duplicated, weak, or misconfigured records.
- DNS Values: Published TXT and MX values used for email authentication.
SPF: Sender Policy Framework
SPF defines which servers and services are allowed to send email for your domain. It is usually published as a TXT record that starts with v=spf1.
SPF is important when you send email through services such as Google Workspace, Microsoft 365, Zoho Mail, Mailgun, SendGrid, Amazon SES, CRM platforms, marketing tools, or hosting mail servers.
Common SPF issues include:
- No SPF record exists.
- More than one SPF record exists on the same hostname.
- The SPF record does not include all sending providers.
- Old providers remain in SPF after migration.
- The SPF record is too complex or hard to maintain.
DKIM: DomainKeys Identified Mail
DKIM uses cryptographic signatures to verify that an email was authorized by the sending domain and was not modified in transit.
DKIM records are usually published as TXT records under selector-based hostnames such as:
selector._domainkey.example.com
To verify DKIM, you need the selector provided by your email service. If DKIM is missing or published under the wrong selector, messages may fail authentication.
DMARC: Domain-Based Message Authentication
DMARC tells receiving mail servers what to do when an email fails SPF or DKIM checks. It is published as a TXT record at:
_dmarc.example.com
DMARC policies may include:
p=nonefor monitoring.p=quarantinefor sending suspicious messages to spam.p=rejectfor rejecting unauthenticated messages.
MX Records and Email Routing
SPF, DKIM, and DMARC help authenticate email, but MX records control where incoming mail is delivered. If MX records are wrong, email may not reach your mailbox even if authentication records exist.
For deeper mail routing diagnostics, use the MX Record Lookup tool together with this email security check.
Email Security and TXT Records
Most email authentication records are published as TXT records. This includes SPF, DKIM, DMARC, and many provider verification records.
If you want to inspect raw TXT values directly, use TXT Record Lookup. For a complete email-focused view, use the Email Security Check page.
Email Security and DNS Propagation
After changing SPF, DKIM, DMARC, or MX records, the new values may not appear everywhere immediately because of DNS caching and TTL values.
If you recently updated email DNS records and still see old results, check DNS Propagation to understand whether the updated records are visible across resolvers.
Common Email Security Problems
- Missing SPF record.
- Multiple SPF records on the same hostname.
- Missing DKIM selector records.
- DMARC record missing or too weak.
- MX records pointing to an old mail provider.
- SPF includes missing after changing email platforms.
- TXT records added to the wrong DNS provider.
- DNS propagation delay after email migration.
When Should You Run an Email Security Check?
- Before launching business email on a domain.
- After moving to a new email provider.
- When emails go to spam.
- When messages fail SPF, DKIM, or DMARC.
- After setting up Google Workspace, Microsoft 365, Zoho, or transactional email services.
- During domain security audits.
- When protecting a brand from spoofing and phishing.
Best Practices for Email Security Records
- Publish one valid SPF record per hostname.
- Enable DKIM signing in your email provider.
- Publish a DMARC record for your domain.
- Start with monitoring if you are new to DMARC, then move toward stricter policies.
- Remove old mail providers from SPF after migration.
- Check MX records together with SPF, DKIM, and DMARC.
- Review email DNS after changing DNS providers or name servers.
Frequently Asked Questions
What does Email Security Check do?
Email Security Check reviews DNS records used for email authentication and routing, including SPF, DKIM, DMARC, and MX records.
Why are SPF, DKIM and DMARC important?
They help receiving mail servers verify whether emails claiming to come from your domain are legitimate, reducing spoofing risk and improving deliverability.
Can missing email records cause spam problems?
Yes. Missing or incorrect SPF, DKIM, and DMARC records can increase the chance that legitimate emails land in spam or fail authentication.
Do MX records affect email security?
MX records mainly control incoming mail routing, but they are part of the overall email DNS setup and should be checked with authentication records.
How long do email DNS changes take?
Changes may appear within minutes or take longer depending on TTL values, DNS cache, and resolver behavior.
Check Email Security Records Online With IPMYP
IPMYP’s Email Security Check tool helps you review SPF, DKIM, DMARC, MX, and related email DNS records for any domain. Enter a domain above, run the check, and use the results to improve email deliverability, reduce spoofing risk, and strengthen domain email security.
