Across 5.5 million domains, 12.8% enforce a DMARC policy that stops spoofing. Is yours one of them?
The FBI booked $3.04 billion of business email compromise losses in 2025. Most of it began with a From line nobody could verify.
Gmail has required DMARC from anyone sending 5,000 messages a day since 2024. Do you clear the bar?
56% of domains publish SPF. Only 22.7% sign anything with DKIM. DMARC needs one of them to line up with your From address.
SPF stops counting at ten DNS lookups, then fails for every message you send. Most records go over without anyone noticing.
Of 5.5 million domains, 15,997 publish MTA-STS. The rest take whatever certificate the connection offers.
Is your domain sick?
Find out in 5 seconds.
The MailDoc runs a full checkup on your email, SPF, DKIM, DMARC, MX and DNSSEC, then hands you the exact prescription to fix what's wrong. Free, and no signup.
How the checkup works
Examine
We read your live DNS the way a receiving mail server does, every record, in the same order, with the same limits.
Diagnose
Each record is graded against the RFCs and triaged: critical, urgent, needs attention, minor.
Prescribe
Every condition comes with the exact fix, written to paste into your DNS. No jargon, no upsell.
Treat
Do it yourself with the prescription, or hand it to someone who has run DMARC monitoring across 2,000+ domains.
The Lab
Run a single test
Need to check just one thing? The Lab has a dedicated test for every part of your email setup, and every one comes with a prescription.
SPF Test
RFC 7208Full chain walk with the exact 10-lookup count. Catches the PermError other checkers miss.
DMARC Test
RFC 9989Tree walk, inheritance, alignment and reporting. Is your policy actually being applied?
DKIM Test
RFC 6376Selector discovery and real key strength. Weak keys fail silently for years.
Spoofability
the scary oneCan somebody send as you right now? One verdict, no hedging.
Sender Readiness
Google, Yahoo, MicrosoftWill the bulk sender rules reject you? Find out before they do.
Bloodwork
DMARC reportsRead your aggregate reports and see who is sending as you. Parsed in your browser.
Health Library
Understand it before you change it
Three guides that assume nothing, written to be read in order by somebody who has been told their email has a problem and given no more detail than that.
DMARC, from a first record to enforcement
GuideThe only record that governs the address your recipient actually sees. What it does, what it does not, and how to reach enforcement without breaking your own mail.
Email authentication, explained by what each part proves
GuideThree records, three different jobs, and only one of them stops somebody sending mail in your name. Here is what each proves and the order to fix them in.
Why your mail lands in spam, in the order worth checking
GuideDeliverability problems have a small number of causes and a reliable order to work through them. Authentication first, because it is the only part you can prove.
Or look a term up in the glossary, or read what a finding means in the list of conditions.
Common questions
How do I know if someone can send email pretending to be my domain?
Put your domain in the box above. The answer depends almost entirely on one record, DMARC, and on the policy it publishes. Without DMARC, or with a policy of p=none, anyone in the world can put your domain in the From line and most inboxes will deliver it. The checkup tells you which of those you are in one line, before any of the detail.
What is a good email authentication score?
Above 85 means nothing serious is wrong. Between 65 and 84 there are real gaps costing you delivery or leaving you exposed. Between 40 and 64 authentication is not doing its job. Below 40 is critical, and for most domains that score it is because anybody can send as them. The score is built from four separate questions rather than one list, so a domain can be excellent at stopping impersonation and still lose marks for reporting it cannot see. A record you have not published at all holds down the questions it would have answered, which is why a domain with nothing scores near zero rather than in the sixties.
Is this actually free, and do you store my domain?
It is free with no account, and there is no paid tier holding the real answer back. Every check reads public DNS, the same records any mail server reads when it decides what to do with your mail. Nothing about a checkup is stored. The only thing this site keeps is a consultation request, and only if you fill one in.
Why does another tool say my SPF is fine when this one does not?
Usually the lookup count. SPF allows ten DNS lookups and the ones inside your includes count against the same ten, so a record that looks short can be over the limit through somebody else’s vendor. Past ten, receivers return a permanent error and SPF fails for every message you send. This walks the whole chain and shows you the count with the tree that produced it.
What should I fix first?
Whatever the chart lists first. Findings are triaged by what they cost you, not by which record they sit in, so the first card is the one doing the most damage. Every card carries the exact record to publish and the standard it comes from.