Check your SPF, DKIM and DMARC records.

Enter a domain and see its email authentication live, exactly as Gmail and Outlook read it. We tell you what is set, what is weak, and what is missing.

Know your DKIM selector? Add it

What the checker is actually reading

When a mailbox provider receives your email, it reads three public DNS records to decide whether to trust it: SPF, which lists the servers allowed to send for your domain; DKIM, a signature that proves the message was not tampered with; and DMARC, which says what to do when a message fails. This tool reads the exact same records, so the result is what Gmail and Outlook see, not a simulation.

Since Google and Yahoo made all three mandatory for volume senders in February 2024, a gap here is no longer a warning, it is a bounce or a spam placement. If the checker flags a missing or weak record, fix it before you send another campaign.

Fix the gap, then send from real infrastructure

Missing a record? The generator builds correct SPF, DKIM and DMARC for you to paste straight into your DNS. But clean authentication is the floor, not the ceiling. Sending cold email at volume still burns a single mailbox fast. HotHawk warms your mailboxes on real Google and Microsoft inboxes and rotates sending across all of them, so you can run 40,000 emails a day and more while your domains stay healthy.

No credit card required.

Frequently asked

How do I check if my domain has SPF, DKIM and DMARC?

Enter your domain above and this tool queries your live DNS for all three records, then tells you what is set and what is missing. Under the hood it reads the same public TXT records a mailbox provider reads when it receives your mail, so what you see is what Gmail and Outlook see.

Why can the checker not find my DKIM record?

DKIM records live at a selector you choose, like selector1._domainkey.yourdomain.com. We probe the common selectors used by Google, Microsoft, Mailchimp and others, but if you use a custom selector, or a provider like Amazon SES that uses a random token, we cannot guess it. Add your selector in the field above and we will check it directly.

What does a DMARC policy of none mean?

p=none means DMARC is in monitoring mode. It collects reports but tells receivers to take no action on messages that fail, so it offers no protection yet. It is the right place to start, but the goal is to move to quarantine and then reject once you have confirmed your legitimate mail passes.

Is my SPF record too permissive?

If it ends in +all it accepts mail from anywhere, which defeats the point. ~all (softfail) is fine while testing, and -all (hardfail) is the strongest. SPF also has a hard limit of 10 DNS lookups. If your record chains too many includes it breaks, so the checker counts them for you.

Do these records guarantee my cold email gets delivered?

No. Passing SPF, DKIM and DMARC stops you being rejected on authentication, but deliverability at scale also rests on warmed mailboxes, sensible volume and a clean reputation. Authentication is the entry ticket. HotHawk runs the rest: warmup on real inboxes and inbox rotation across many mailboxes.

Send cold emails that get delivered. Never miss a positive reply.

Serious deliverability paired with the best reply management in the market.

Start your 7 day free trial

No credit card required.

Premium warmup

Join our premium warmup pool

We have over 50,000 Google and Microsoft mailboxes in the pool and we are opening to the public soon. Be first to know when it's open.

Special offer

Get 50% more sending, FREE.

Send 50% extra emails per month on any plan, every month for as long as you're with us. Enter your details and we'll email your promo code over.

Your new boosted limits

  • Starter 100,000 150,000
  • Scale 300,000 450,000
  • Infra 500,000 750,000

Applies to any plan. One per customer.