BounceLens

SPF, DMARC and DKIM checker

Type your domain to see whether Gmail, Outlook and Yahoo can trust the email you send. One check covers all three records and explains each problem in plain words.

Why these three records matter

Anyone can put your domain in the "From" line of an email. SPF, DKIM and DMARC are how receiving servers tell your real emails from fakes. Without them, your emails are more likely to land in spam, and scammers can send email that looks like it came from you.

Since February 2024, Gmail and Yahoo require SPF or DKIM from everyone who sends to them, and SPF, DKIM and DMARC from bulk senders (around 5,000 or more emails a day). Microsoft brought in similar rules for Outlook.com in 2025.

What each record does

RecordQuestion it answersWhere it lives
SPFWhich servers may send email for this domain?TXT record on the domain, starts with v=spf1
DKIMWas this email really signed by the domain and not changed on the way?TXT record at selector._domainkey.domain
DMARCWhat should receivers do with email that fails SPF and DKIM, and where should reports go?TXT record at _dmarc.domain, starts with v=DMARC1

Common SPF mistakes

Too many DNS lookups (more than 10)

Every include:, a, mx and redirect costs a lookup, and the includes inside includes count too. Above 10, receivers stop and treat your SPF as broken. This is the most common SPF error, usually after adding tool after tool (CRM, newsletter, help desk). Remove services you no longer use, or replace some includes with their ip4: ranges.

Two SPF records

A domain may have only one SPF record. When a new tool tells you to "add this SPF record", don't add a second one: merge its include: into the record you have.

Ending with +all or nothing

+all allows every server in the world to send as you. End the record with ~all (suspicious) or -all (reject) instead.

Common DMARC mistakes

Staying on p=none forever

p=none is the right place to start: it changes nothing and sends you reports. But it doesn't stop fake emails. When the reports show only your own services, move to p=quarantine, then p=reject.

No reporting address

Without rua=mailto:… you never learn who sends email as your domain. Add an address, or a free DMARC report service.

A good first record looks like this:

v=DMARC1; p=none; rua=mailto:[email protected]

About the DKIM result

DKIM keys sit under a "selector" name that each email provider picks, and there is no public list of them. BounceLens tries the common ones (Google, Microsoft 365, Mailchimp, SendGrid, Zoho and others). If none match, it doesn't mean DKIM is missing; check your provider's settings for the selector name.

Questions

Is my domain sent anywhere?

Only to Cloudflare's public DNS (1.1.1.1), which your browser asks directly. BounceLens doesn't store the domains you check.

The check says "pass" but my emails still go to spam. Why?

These records prove who you are; they don't make the content wanted. Spam placement also depends on your sending history, complaint rate, and how many of your emails bounce. Cleaning your list with the email list checker helps with the bounces.

More free checks