Tools
Email DNS Checker — MX, SPF & DMARC
Check a domain's email DNS records, including MX, SPF, DMARC and authoritative nameservers.
What this report checks
Email DNS Checker combines nameservers, MX, SPF and DMARC in one report and explains which layer to repair first.
| Signal | Healthy result | Problem detected | Recommended action |
|---|---|---|---|
| Delegation | NS points to the DNS panel you manage | Changes made at a non-authoritative provider | Edit records where the public nameservers are hosted. |
| Receiving | MX matches the current mailbox provider | Missing, stale or conflicting MX | Restore the complete provider MX set before testing inbound mail. |
| Sending | One maintainable SPF policy | Missing, duplicated or risky SPF | Merge authorised senders and validate the lookup chain. |
| Protection | A staged DMARC policy with reporting | No policy or enforcement without visibility | Begin monitoring, verify alignment and enforce gradually. |
From result to verified repair
- 1Enter only the registrable domain.
- 2Fix delegation before individual records.
- 3Repair MX, then SPF and DMARC with the linked specialist tools.
- 4Recheck after TTL expiry and confirm a real inbound and outbound message.
What this tool cannot prove
- The report is a point-in-time view of public DNS caches.
- DKIM requires a known selector and is checked separately.
- Healthy DNS cannot predict reputation, filtering or inbox placement.
How to run a useful DNS check
- 1Enter only the root domain, for example
example.com—not an email address or URL. - 2Run the check after saving records at the authoritative DNS provider.
- 3Compare every public answer with the Name, Value and Priority shown in mailbox setup.
- 4Correct missing or conflicting records, allow caches to refresh, then check again.
Records and fields checked
| Record | Name / Host | What the value means | Priority |
|---|---|---|---|
| MX | @ | Where incoming email is delivered | Required for MX |
| TXT (SPF) | @ | Which services may send for the domain | — |
| TXT (DMARC) | _dmarc | Authentication policy and reporting | — |
| NS | @ | Which provider is authoritative for DNS | — |
Common DNS Checker problems
- Entering
https://example.cominstead ofexample.com. - Editing records at the registrar while another provider's nameservers are authoritative.
- Checking immediately while the previous TTL is still cached.
- Publishing two SPF records or appending the domain twice to a hostname.
Overview
Check a domain's email DNS records, including MX, SPF, DMARC and authoritative nameservers.
Authentication is the foundation
TXT proves control. MX directs incoming mail. SPF, DKIM and DMARC give receivers evidence that your messages are legitimate.
Setting up email for a domain you own? See the catch-all inbox and its limits before changing DNS.
Related guides
Frequently asked questions
Does DNS Checker change my records?
No. It only reads public DNS answers.
Why does the old value still appear?
Resolver caches can retain the previous value until its TTL expires.
Why is a record missing after I saved it?
Confirm you edited the authoritative DNS provider and did not duplicate the domain in the Host field.