02 · Email check
Email check: do your emails end up in spam?
See whether SPF, DKIM and DMARC are set up correctly. They are three DNS records that affect whether your emails reach the inbox or end up in the spam folder.
- Only public DNS records are read
- No test emails are sent
- The domain is not stored
How it works
How the check goes
-
You type your domain
Type the domain, for example example.com, or an email address, and we use only the part after the @. You do not need to type www or https://.
-
We look up the records in DNS
Our server asks DNS for the domain’s MX records, SPF record and DMARC record and tries a number of common DKIM selectors. These are lookups only: no mail server is contacted and no email is sent.
-
You get an answer and suggestions
Each record gets a status, and you see what it looks like. If DMARC is missing you get a suggested record to start from, and for SPF when we recognise the email service. Always follow your email provider’s own instructions first.
Good to know about the method
- DKIM keys cannot be listed in DNS. We try common selector names. If no key is found, it does not mean that DKIM is switched off.
- A correctly set up domain raises the chance that your emails reach the inbox, but each receiver’s filter decides. We cannot promise delivery.
- We do not see the content of the emails, the sender’s reputation or whether the domain is on any blocklist.
- It is a pure DNS check. No SMTP connection is made and no test emails are sent.
- The domain is not stored. The only things stored are counters that limit the number of checks, per connection and per domain. They apply for five minutes and do not contain the domain in plain text.
Why do my emails end up in spam?
The receiver’s mail server decides for every email whether it goes to the inbox or the spam folder. One of the first questions is whether the server that sent the email is really allowed to send in your domain’s name. If that cannot be checked, or does not match, the risk that the email ends up in spam goes up. This applies also to emails sent automatically from the website’s contact form, the booking system or the invoicing software.
The answer is in three records in the domain’s DNS: SPF, DKIM and DMARC. Since February 2024 Google and Yahoo have required them: SPF or DKIM for all senders, and SPF, DKIM and DMARC for anyone who sends large volumes, at Google 5,000 emails or more a day to Gmail. The records are only part of the picture, though: the content, the sender’s reputation and the receiver’s own filters also matter.
What is SPF?
SPF is a list in DNS of the servers and services that may send email for your domain. The receiver compares the server that sent the email with the list. It is a TXT record on the domain, starts with v=spf1 and should end with ~all or -all. A domain should have only one SPF record, and it may require at most ten DNS lookups, counting the records it refers to. SPF is seldom enough on its own: it does not check the sender address that the receiver sees, and it works worse when email is forwarded.
What is DKIM?
With DKIM the sender’s server signs every email with a private key. The public key is in DNS under a selector name that your email provider chooses, and the receiver uses it to see that the email comes from the right domain and was not changed on the way. DKIM therefore has to be switched on at the provider, who gives you the record to add.
What is DMARC?
DMARC ties SPF and DKIM together. It is a TXT record on _dmarc.example.com that says what the receiver should do with email where neither SPF nor DKIM matches the sender domain: p=none means no action, p=quarantine that the email should be treated as suspicious and p=reject that it should be rejected. With rua= you say where summary reports should be sent.
What do I do if something is missing?
First find out which services send email in your domain’s name: the email service, but often also contact forms, newsletters and invoicing software. Then follow each provider’s own instructions for SPF and DKIM, but gather all services in one single SPF record, and add the records where the domain’s DNS is managed, at the domain registrar or the web host. After that add DMARC with p=none and a rua address, read the reports for a while and tighten to quarantine or reject only when your own emails pass the check. A change in DNS is often visible within an hour but can take up to a day.
If you would rather not do it yourself, we fix SPF, DKIM and DMARC for you for from SEK 1,495 including VAT. See what the package includes. If you also want to check the website itself you can test the website for free.
Do emails you receive end up in the spam folder?
Then this check is not what helps, because SPF, DKIM and DMARC are set up by whoever sends. As the receiver in Outlook, Gmail or Mail on your iPhone you can move the email to the inbox, mark it as “not spam” and add the sender to your contacts. You can, however, check the sender’s domain here: only public records are read, so it is fine to test someone else’s domain.
Fixed packages
Do you want to avoid doing it yourself?
Email settings need only small changes, but they easily go wrong. We take care of them for you, as a package. Prices include VAT, and the scope is confirmed in writing before we start.
Frequently asked questions
Questions about the email check
Is any email sent when I test?
No. The check only looks up public DNS records for the domain. We do not connect to any mail server and send no test email, neither to you nor to anyone else.
Why was no DKIM found?
DKIM keys are stored under a name, a so-called selector, that the email service chooses, and it is not possible to list all names in DNS. We therefore try a number of common selectors. If your provider uses another name we find no key even though DKIM works, and that is why it is a note and not an error. Send an email to yourself and look for dkim=pass for your own domain in the email’s header, in Gmail under “Show original”, or ask the provider which selector is used.
What do p=none, quarantine and reject mean?
That is the DMARC record’s policy, that is, what the receiver should do with email that claims to come from your domain but does not pass the check. none means that nothing is done and the emails are delivered as usual, and that you can get reports if you give a rua address. quarantine means that the email should be treated as suspicious, usually by ending up in the spam folder. reject means that the receiver should reject the email. Start with none and tighten only when the reports show that your own emails pass the check.
Can I test someone else’s domain?
Yes. The check reads only records that anyone can look up in DNS and does not connect to the domain’s mail server. It is a way to see whether a supplier’s or customer’s email settings lack something, but it is the owner of the domain who can correct the records.
How long does it take before a change takes effect?
It depends on how long older answers may be kept in DNS, the so-called TTL. A change is often visible within an hour, but it can take up to a day. Check again after a while. If the change is not visible then, check that the record is on the right name and written exactly as the provider says.
My emails end up in spam although everything looks right. Why?
SPF, DKIM and DMARC only show that the email comes from the right sender. The receiver’s filter also weighs the content, the sender’s reputation, how many emails are sent, whether the links look suspicious and what the receiver has marked as spam. We cannot see that from here. Ask the receiver to add your address to their contacts, and ask us in the chat if it continues.
Do you want us to correct the records for you?
Tell us what the check showed and we say what needs to change. You get a price in writing before we start.