Skip to content

SPF, DKIM and DMARC record parser

Paste a TXT record taken from dig, nslookup or your DNS panel. The record type is detected, the syntax is checked, and critical issues, warnings and notes are listed. No live DNS query is made; the record never leaves your browser.

Free tool · Infrastructure

You can paste the record quoted (dig/nslookup output) or plain; multi-part TXT strings are joined. If you paste several records, each is analysed separately.

Parsed in your browser; the record is not sent and no DNS query is made.

How do I get the record?
  • dig +short TXT example.com
  • dig +short TXT selector._domainkey.example.com
  • dig +short TXT _dmarc.example.com
  • nslookup -type=TXT _dmarc.example.com

SPF record

0 critical · 0 warnings · 2 info

Issues

  • Info~all (softfail): unauthorised senders are flagged but usually not rejected. Normal during rollout; consider -all once the sender list is final.

  • InfoThe lookup count (3) is a lower bound: lookups inside records called through include and redirect could not be counted because those records are unknown. The real number may be higher.

Record summary

Version
spf1
Number of mechanisms
5
DNS lookups (lower bound)
≥ 3
Final rule (all)
~all
Included domains
_spf.google.com, spf.protection.outlook.com
IP ranges
ip4: 1 · ip6: 0

Record parts

Record parts
TermResult if matchedMeaning
ip4:203.0.113.0/24PassAllows an IPv4 address or range
include:_spf.google.comPassAlso uses another domain's SPF recordCounts as a DNS lookup
include:spf.protection.outlook.comPassAlso uses another domain's SPF recordCounts as a DNS lookup
mxPassAllows the addresses of the domain's mail servers (MX)Counts as a DNS lookup
~allSoftfailResult when no other rule matched

What we count and how

  • SPF DNS lookups = the sum of include + a + mx + ptr + exists + redirect terms (RFC 7208, limit 10). ip4, ip6 and all are not counted.
  • This number is computed from the pasted record only; lookups inside include/redirect are not added. The real number is equal to or higher than this value.
  • DKIM key length = the bit length of the RSA modulus read from the DER inside the base64-decoded p= value. If the DER cannot be read, no length is given.
  • Multi-part TXT strings are joined without a separator (DNS behaviour).

This tool only checks the text you paste for syntax and common configuration mistakes. It does not check that the record is actually published for your domain, what the included records contain, or whether your sending systems are aligned; results are a preliminary assessment. Verify policy changes against DMARC reports before putting them live.

Shall we review your email authentication, your sending systems and your DMARC reports together?

Request a meeting

01

How to use

  1. A

    Get the record: dig +short TXT yourdomain.com (SPF), dig +short TXT selector._domainkey.yourdomain.com (DKIM) or dig +short TXT _dmarc.yourdomain.com (DMARC). On Windows use nslookup -type=TXT, or copy it from your DNS panel.

  2. B

    Paste the output into the box; the tool detects the record type. If you paste several records, each is analysed separately.

  3. C

    In the issue list look at critical items first, then warnings; the record summary and the parts table show what the record says. Fix it in your DNS panel and paste the record again to test.

02

What do SPF, DKIM and DMARC do?

SPF lists in DNS which servers may send mail on behalf of your domain. DKIM lets the sending server add a signature made with a private key and lets the receiver verify it against the public key in DNS. DMARC ties the two together: it requires the visible From domain of a message to align with the SPF or DKIM result and tells the receiver what to do on failure (none, quarantine, reject); it also sends you reports.

Together they make it harder to abuse your domain in forged email and reduce the risk of your own messages landing in spam. Since 2024 Google and Yahoo expect bulk senders, those sending thousands of messages a day, to configure SPF, DKIM and DMARC together. This tool is not a compliance or certification measure; it is a checking aid that helps you review your records.

03

The SPF limit of 10 DNS lookups

When SPF is evaluated, each include, a, mx, ptr, exists and redirect term counts as one DNS lookup, and the terms inside included records count towards the same total. If the total exceeds 10, the receiver treats SPF as broken (permerror) and validation fails. The limit is easily exceeded by domains that include several email marketing and cloud services.

The tool can only count the terms in the record you paste; because it cannot see what the included records contain, the number it shows is a lower bound. If you are near the limit, parse each included domain's record separately and add up the total yourself. The remedy is usually to delete unused services, write fixed addresses as ip4/ip6, or split senders across subdomains.

04

Reading a DKIM key and a DMARC policy

In a DKIM record p= is the public key; 2048 bits is recommended for RSA, 1024 bits is still seen but considered weak. t=y is test mode and should be removed when you are done. If p= is empty the selector has been revoked. The tool estimates the key length from the base64 data; if the data is not in the expected format it gives no length.

With DMARC a safe path is to start with p=none and watch the reports arriving at your rua address, and once legitimate senders are aligned through SPF/DKIM to move gradually to quarantine and then reject, using pct. Without rua you cannot see who sends on behalf of your domain; ruf (forensic reports) can contain personal data and should be used with care.

FAQ

Is the record I paste sent anywhere?
No. Parsing runs as code in your browser; the record is not sent to any server or stored, and the tool makes no live DNS query.
Why does the tool not fetch the record from DNS itself?
A browser cannot make direct DNS queries; that would require sending your domain to a server. Copying the record from dig, nslookup or your DNS panel protects your privacy and also lets you check a record that is not yet published (a draft).
Should I use ~all or -all in SPF?
-all asks for unauthorised senders to be rejected; ~all is a softfail. If you use DMARC, ~all is often enough because the DMARC policy makes the real decision. If your sender list is complete and stable, -all is clearer.
What happens if I exceed the 10-lookup limit?
The receiver ends SPF evaluation with an error (permerror) and SPF does not pass. If DMARC relies on SPF, alignment fails as well. That is why removing unneeded includes matters.
Why is the key length sometimes not shown for a DKIM record?
The length is found by base64-decoding the p= value and reading it as an RSA key. If the data is not in the expected DER format (for example truncated, or a different key type), the tool does not guess and notes this as information.
Can I paste more than one record?
Yes. Each line of dig output counts as a separate record; if there is more than one SPF or DMARC record this is reported as an error, because a name may have only one.

Protect the reputation of your email

Let us review your email infrastructure and DNS configuration together, including domain email authentication, an inventory of sending systems and DMARC report monitoring. In a free discovery call we discuss where you stand.