Tool version 1.0.0
Email Authentication Inspector
Explains public SPF, DKIM selector and DMARC records for a domain without sending email or accessing an inbox.
Quick answer
- What is it?
- Explains public SPF, DKIM selector and DMARC records for a domain without sending email or accessing an inbox.
- What does it accept?
- Domain and optional DKIM selector. Validate domain syntax and selector length.
- What does it produce?
- SPF tree, DMARC policy, DKIM record status, syntax findings and plain language next steps.
Inputs
Input contract
Domain and optional DKIM selector. Validate domain syntax and selector length.
Results
Output anatomy
SPF tree, DMARC policy, DKIM record status, syntax findings and plain language next steps.
Method
Processing path
Server performs bounded DNS TXT lookups, parses recognized mechanisms and detects lookup count or alignment concerns.
Limits
Tradeoffs and limits
Input quality, browser memory, remote server behavior and public API availability can affect a result. The finding describes the supplied material at the time of the test; it does not prove intent or future behavior.
Advanced
Power features
SPF include expansion with a strict depth cap, DNS lookup count, DMARC reporting address extraction and raw record view.
FAQ
Questions about Email Authentication Inspector
What does Email Authentication Inspector accept?
Domain and optional DKIM selector. Validate domain syntax and selector length.
How is the result produced?
Server performs bounded DNS TXT lookups, parses recognized mechanisms and detects lookup count or alignment concerns.
What will I receive?
SPF tree, DMARC policy, DKIM record status, syntax findings and plain language next steps.
Is the input private?
Server queries public DNS. Full TXT values are not written to analytics.
What are the main limitations?
Results depend on the quality, completeness and public availability of the supplied input. Review the evidence before making a high-impact decision.