Most deliverability problems aren’t caused by what you send, they’re caused by how your domain is configured. A sender with clean lists and great content can still end up in spam if their SPF record is broken, their DKIM key isn’t published, or their DMARC policy is missing. The problem is invisible until something goes wrong.

This free email deliverability test checks your authentication setup from the outside, reading the same DNS records a receiving mail server looks up when your email arrives. Enter a sending address or domain and see whether SPF, DKIM and DMARC are configured correctly, and what to fix if they’re not.

What this email deliverability test checks

Most deliverability testing tools either require you to send a test email to a seed address or focus only on content scoring. This one focuses on your domain’s authentication layer, the DNS configuration that mailbox providers check before they even look at your content.

Here’s what the test evaluates:

SPF (Sender Policy Framework): Whether your domain publishes exactly one SPF record, whether every term in it is readable, how many DNS lookups it needs against the limit of 10 (following each include: down the chain), and how it ends. An SPF record that exists but is malformed or over the limit fails just like a missing one.

DKIM (DomainKeys Identified Mail): Whether a DKIM public key is published at one of 24 common selectors, or at the selector you enter. This confirms the key exists in DNS. Checking an actual signature needs a real email, which this test doesn’t send.

DMARC: Whether a single valid DMARC record exists, what policy it’s set to, what share of mail it applies to, and where aggregate reports go. A p=none policy with no reporting address is functionally useless: you’re getting no data and enforcing nothing.

MX records: Whether the domain can receive replies and bounces. It carries less weight than the other three.

The score out of 10 is weighted toward authentication: SPF, DKIM and DMARC are worth 3 points each and MX is worth 1. The result only reads “Good” when all three authentication checks pass. A passing result doesn’t guarantee inbox placement (content, sending reputation and list hygiene all factor in), but failing authentication is one of the clearest reasons email gets blocked or filtered, and it’s fixable.

The test doesn’t check blacklists. They list sending IPs, and from a domain name alone the only IP available is the website’s, which for most brands isn’t the one their ESP sends from.

Why email deliverability testing matters more than it used to

Getting email delivered used to be relatively forgiving. Mailbox providers were lenient, authentication was loosely enforced, and even misconfigured domains could often squeak through.

That window has closed.

In early 2024, Google and Yahoo updated their requirements for bulk senders: SPF and DKIM are both required, DMARC is required (at minimum p=none), and one-click unsubscribe is mandatory for marketing mail. Microsoft followed with similar requirements for Outlook. These aren’t spam filter preferences; they’re published requirements with real enforcement behind them.

A broken SPF record usually shows up the same way: open rates slide for no obvious reason, and nobody looks at DNS until weeks later. The fix itself takes minutes. Testing your authentication whenever something changes isn’t paranoia, it’s maintenance.

Understanding your results

Each check comes back with the record the test found, so you can see exactly what receivers see.

SPF: valid. One record, every term readable, within the 10-lookup limit, ending in ~all (flag servers that aren’t listed) or -all (reject them). This is the baseline.

SPF: needs attention or failed. The most common causes are two SPF records on the same domain (receivers treat that as an error, so merge them), too many include: entries pushing the record past 10 lookups, an include pointing at a domain with no SPF record, or an ending of +all or ?all that tells receivers nothing useful. Use our free SPF record generator to rebuild the record correctly.

DKIM: key found. A public key is published at the selector shown. If you’re using an ESP, make sure you’ve finished DKIM setup in both their platform and your DNS; it usually means adding a CNAME or TXT record at a specific subdomain.

DKIM: not confirmed. No key was found at the selectors the test tried. That doesn’t always mean DKIM is missing: your ESP may use its own selector (enter it and test again) or sign from a subdomain such as send.yourbrand.com (test that domain). If you set DKIM up recently, allow up to 48 hours for DNS to propagate.

DMARC: enforced. The policy is p=quarantine or p=reject, so mail that fails authentication is sent to spam or rejected. This is real protection against spoofing.

DMARC: monitoring only. The policy is p=none. With a reporting address, that meets the Gmail and Yahoo minimum and tells you who is sending as your domain. Once the reports look clean, move to p=quarantine. Without a reporting address, add one first.

DMARC: missing or invalid. No usable record exists at _dmarc.yourdomain.com. This is one of the most common gaps we see. Use our free DMARC record generator to create one.

How email authentication affects deliverability

SPF, DKIM, and DMARC are sometimes described as separate checks, but mailbox providers evaluate them as a system. Here’s roughly how that works in practice:

When an email arrives, the receiving server checks SPF first: is this IP authorized to send from this domain? Then it verifies the DKIM signature: was this message signed by the domain it claims to be from? Then it checks DMARC: does the domain in the From: header align with the domain that passed SPF or DKIM? And finally, what does the DMARC policy say to do with failures?

An email that passes all three checks is treated very differently from one that fails even one. Consistent failures, or a missing DMARC record, signal to mailbox providers that a domain isn’t properly managed. Over time, that affects your sender reputation, which affects deliverability even for emails that would otherwise be fine.

The good news: authentication is entirely in your control. It’s DNS configuration. It doesn’t require a new platform, a new process, or budget. It just requires knowing what’s wrong.

Authentication is the foundation. Once it’s solid, the rest of deliverability work, list hygiene, engagement metrics, content quality, sits on top of it properly. If you found gaps in your SPF or DMARC setup, our free SPF record generator and free DMARC record generator will help you fix them.

And if you want to check your content alongside your authentication, whether your subject line or body copy is triggering spam filters, our free email spam checker covers that side of the picture.