Free tool · No sign-up
SPF, DKIM & DMARC Checker
Check whether a domain publishes the three records that stop anyone sending mail as you: SPF, DMARC, and a DKIM selector. Reads each record back over DNS-over-HTTPS, explains what its policy actually enforces — an SPF that ends in ~all is not the same as one ending in -all — and tells you what is missing.
Method & assumptions
- SPF lists who may send for the domain; the qualifier on its terminal all decides what happens to everyone else — -all rejects, ~all soft-fails, ?all is neutral, +all passes anyone.
- DMARC ties SPF and DKIM to the visible From address and sets a policy: p=none only monitors and is spoofable in practice, while quarantine and reject are enforced.
- DKIM is checked by probing a handful of common selectors. A domain can use a selector we do not guess, so a blank DKIM result is not proof it is missing.
- Only published DNS records are read — this does not send a test message or verify signing keys actually work.
- This tool sends the domain you enter to Cloudflare's public resolver to read its records. Nothing is sent to JCIT, and the analysis runs entirely in your browser.
Other tools
More on the bench
- 01
DNS Lookup
Every record for a domain, from your browser. - 02
SSL Certificate Checker
Expiry, chain, and issuer at a glance. - 03
Supabase Security Auditor
Point it at your project, find the holes. - 04
JWT Decoder
Paste a token, read what is inside. - 05
Secret & .env Scanner
Paste code or a .env, catch the leaked keys. - 06
Security Headers Scanner
Enter a URL, grade its headers. - 07
CORS Tester
See exactly what a URL allows cross-origin. - 08
Base64 Encode / Decode
Text or files, both directions.
Software engineering
We write the software
behind tools like these
Anyone whose domain sends email and wants to know it cannot be spoofed by a stranger.
- Free diagnostics
- Same-day across most of the metro
- Named technicians
- No fix, no labour charge