Skip to content
Clinic open · free diagnosis, no appointment needed2,000+ domains monitored

Is your domain sick?
Find out in 5 seconds.

The MailDoc runs a full checkup on your email, SPF, DKIM, DMARC, MX and DNSSEC, then hands you the exact prescription to fix what's wrong. Free, and no signup.

A full checkup in about 5 seconds. See what Gmail, Outlook and an attacker see. No signup.

How the checkup works

01

Examine

We read your live DNS the way a receiving mail server does, every record, in the same order, with the same limits.

02

Diagnose

Each record is graded against the RFCs and triaged: critical, urgent, needs attention, minor.

03

Prescribe

Every condition comes with the exact fix, written to paste into your DNS. No jargon, no upsell.

04

Treat

Do it yourself with the prescription, or hand it to someone who has run DMARC monitoring across 2,000+ domains.

Common questions

How do I know if someone can send email pretending to be my domain?

Put your domain in the box above. The answer depends almost entirely on one record, DMARC, and on the policy it publishes. Without DMARC, or with a policy of p=none, anyone in the world can put your domain in the From line and most inboxes will deliver it. The checkup tells you which of those you are in one line, before any of the detail.

What is a good email authentication score?

Above 85 means nothing serious is wrong. Between 65 and 84 there are real gaps costing you delivery or leaving you exposed. Between 40 and 64 authentication is not doing its job. Below 40 is critical, and for most domains that score it is because anybody can send as them. The score is built from four separate questions rather than one list, so a domain can be excellent at stopping impersonation and still lose marks for reporting it cannot see. A record you have not published at all holds down the questions it would have answered, which is why a domain with nothing scores near zero rather than in the sixties.

Is this actually free, and do you store my domain?

It is free with no account, and there is no paid tier holding the real answer back. Every check reads public DNS, the same records any mail server reads when it decides what to do with your mail. Nothing about a checkup is stored. The only thing this site keeps is a consultation request, and only if you fill one in.

Why does another tool say my SPF is fine when this one does not?

Usually the lookup count. SPF allows ten DNS lookups and the ones inside your includes count against the same ten, so a record that looks short can be over the limit through somebody else’s vendor. Past ten, receivers return a permanent error and SPF fails for every message you send. This walks the whole chain and shows you the count with the tree that produced it.

What should I fix first?

Whatever the chart lists first. Findings are triaged by what they cost you, not by which record they sit in, so the first card is the one doing the most damage. Every card carries the exact record to publish and the standard it comes from.