Domain Email Security Checker: SPF, DMARC, DKIM, MX avatar

Domain Email Security Checker: SPF, DMARC, DKIM, MX

Pricing

Pay per event

Go to Apify Store
Domain Email Security Checker: SPF, DMARC, DKIM, MX

Domain Email Security Checker: SPF, DMARC, DKIM, MX

Check any list of domains for email authentication and spoofing protection: SPF (including +all and the 10-lookup limit), DMARC policy and reporting, DKIM keys on 30 common selectors, MX and mail provider, MTA-STS, TLS-RPT and BIMI. A-F grade and a plain list of issues per domain.

Pricing

Pay per event

Rating

0.0

(0)

Developer

Dodge Sucharda

Dodge Sucharda

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

12 hours ago

Last modified

Share

Check a list of domains for email authentication and spoofing protection in one run. For each domain you get an A-F grade, a plain-English list of problems, and the raw records: SPF, DMARC, DKIM (on 30 common selector names), MX and mail provider, MTA-STS, TLS-RPT and BIMI.

$3 per 1,000 domains. A domain that does not exist is a valid result (grade F). Invalid input and DNS outages are free.

Good for

  • Deliverability audits: find why a client's email lands in spam
  • Security and IT agencies: find prospects whose domains can be spoofed (no DMARC, or p=none)
  • Vendor and supply-chain checks: review suppliers' email protection
  • Monitoring your own domains after DNS changes

What is checked

AreaChecks
SPFPresent, only one record, ends in -all/~all (flags +all and ?all), top-level DNS lookups against the limit of 10, includes
DMARCPresent, valid policy, p=none (monitoring only), pct below 100, aggregate reports (rua) set
DKIMKeys found on 30 common selectors (Google, Microsoft 365, SendGrid, Mailchimp/Mandrill, Amazon SES, Zoho, Fastmail, HubSpot and more), key type and approximate size, revoked keys
MXMail servers, detected provider (Google Workspace, Microsoft 365, Proofpoint, Mimecast and others), null MX
ExtrasMTA-STS, TLS-RPT, BIMI

Grade: A no problems; B one warning; C two or more warnings; D one error; F two or more errors, or the domain does not exist.

Output (one row per domain; real result for example.com, shortened)

{
"domain": "example.com",
"status": "ok",
"exists": true,
"grade": "A",
"errors": 0,
"warnings": 0,
"issues": [
{"severity": "notice", "code": "dmarc_no_reports", "message": "DMARC has no rua= address, so no aggregate reports are collected."},
{"severity": "notice", "code": "null_mx", "message": "Null MX: the domain states it never receives email."}
]
}

Each row also includes the raw spfRecord, dmarcRecord, mx, dkim, nameservers and more.

Limits

  • DKIM selectors can't be listed from DNS, so only 30 common names are tried. "Not found" can mean the domain uses a custom selector; it is reported as a notice, not an error.
  • The SPF lookup count covers the top-level record, not every nested include.
  • It only reads public DNS. No emails are sent and no servers are probed.