Email Health Checker
Audit the mail setup of a domain end to end - MX, SPF, DMARC, DKIM and blacklists - with a report you can send a customer.
Check a domain
Health score
Nothing checked yet
What took points off
Checks
Seven records decide whether a receiver trusts mail from this domain. Each one is read live, then judged on what a receiver actually does with it.
MX
Where mail addressed to this domain is delivered, and whether those hosts resolve.
Not checked yet.
SPF
Which servers may send as this domain. The include tree is followed and the 10 lookup limit counted.
Not checked yet.
DMARC
What a receiver should do when SPF and DKIM fail, and where the reports go.
Not checked yet.
DKIM
Selectors cannot be listed from DNS. A clean result here means none of the selectors we know about are published, never that the domain has no DKIM.
Not checked yet.
MTA-STS
Forces TLS between sending servers. The published policy is fetched and checked against the real MX hosts.
Not checked yet.
TLS-RPT
Where a receiver reports a failed TLS negotiation, so a broken certificate is visible instead of silent.
Not checked yet.
BIMI
The logo shown beside a message in some clients. Optional, and never counted against the score.
Not checked yet.
Blacklists
The mail hosts, the apex address and any single-host ip4: mechanism, checked against the DNSBLs we trust.
No lists queried yet
Run a check and every list is queried from this server, one batch at a time.
Written report
Claude turns the findings above into something you can send a customer. The score is worked out here, not by the model.
No report yet
Finish a check first. The report is built from the findings held on the server, never from anything this page sends back.