Skip to content
CloudkuCloudku

SPF, DKIM & DMARC Checker

Check whether your domain has correct SPF, DKIM and DMARC records, the three key requirements for keeping business email out of spam. Below, a generator helps you build the right records.

SPF & DMARC Generator

Select the services that send email on behalf of your domain, then copy the result into DNS as a TXT record.

SPF (TXT record at @)

DMARC (TXT record at _dmarc)

Free, no sign-up. Everything runs in your browser.

The order to set up SPF, DKIM and DMARC

  1. SPF: create a single TXT record v=spf1 ... ~all that lists every service sending email for your domain (mail server, Google Workspace/Microsoft 365, newsletter tools, and so on).
  2. DKIM: enable it in your email provider’s admin panel. They will give you a selector name and a public key value to add to DNS.
  3. DMARC: start with p=none and a rua address to receive reports. Once reports show all legitimate mail passes SPF/DKIM, step up to p=quarantine and then p=reject.

What the results mean

  • Good: the configuration follows recommended practice.
  • Needs attention: it works, but protection isn’t at full strength yet, for example DMARC is still p=none.
  • Problem: the record is missing or invalid, so the domain’s email is easy to spoof and likely to land in spam.

To view other DNS records directly, use DNS Lookup.

FAQ

Frequently asked questions

What do SPF, DKIM and DMARC do?

SPF lists which servers may send email on behalf of your domain. DKIM adds a digital signature to every message so its content cannot be forged. DMARC tells receiving servers what to do when a message fails SPF or DKIM, and where to send reports.

Why does my email land in spam even though I have SPF?

Since February 2024, Google and Yahoo require all senders to have SPF or DKIM, and bulk senders (more than 5,000 messages a day to Gmail) must have SPF, DKIM and DMARC together. IP reputation, reverse DNS (PTR) and message content also play a role.

Why can’t I have two SPF records?

The SPF standard (RFC 7208) allows only one v=spf1 record per domain. With two, the check returns “permerror” and many servers treat SPF as failed. Merge all includes into a single record.

What is the SPF 10 DNS lookup limit?

When evaluating SPF, a receiving server may perform at most 10 DNS lookups (from the include, a, mx, ptr, exists and redirect mechanisms, including those nested inside includes). Beyond that, SPF is treated as an error. Remove includes you don’t use.

Why isn’t my DKIM detected?

A DKIM record lives under a specific selector name, for example google._domainkey.domain.com. This tool checks commonly used selectors. If your email provider uses a different selector, enter that selector name manually.

Business email landing in spam?

Cloudku’s engineers can review and clean up your domain’s DNS and email configuration.

Talk to our team