Email Authentication Configuration Audit

Review supplied SPF, DKIM and DMARC structure and declared domain alignment without DNS or message checks.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Review mail records controls

The domain itself. The audit does not fetch it; it only labels the findings.

One record only. include, a, mx, ptr, exists and redirect are counted but never looked up: this page makes no DNS queries.

A public DNS key record (v=DKIM1) or a DKIM-Signature header (v=1). Public values only; the audit never accepts or stores secrets.

The record published at _dmarc. The p tag is required for a policy record and v must come first.

The RFC5321.MailFrom domain used by the SPF check in this scenario.

The RFC5322.From domain. DMARC compares SPF and DKIM against this domain.

The d= value from the signature, or the selector domain you are testing for DKIM alignment.

Optional but required for a relaxed result. Enter the registered domain, for example example.com. This page has no public suffix list, so it never guesses one and never infers a boundary itself.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use Email Authentication Configuration Audit

  1. Supply the domain the records are published for and spf record (txt) using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the email auth configuration audit.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: Email Authentication Configuration Audit

Check supplied SPF, DKIM and DMARC record structures and declared alignment scenarios. This example uses synthetic public data.

You add
Domain the records are published for: example.com SPF record (TXT): v=spf1 ip4:203.0.113.10 ip6:2001:db8::1 a mx include:mailer.example.net -all DKIM key record or signature header: v=DKIM1; k=rsa; p=AQIDBAUGBwgJCgsMDQ4PEBESExQVFhcYGRobHB0eHyAhIiMkJSYnKCkqKywtLi8w DMARC record (TXT): v=DMARC1; p=quarantine; adkim=s; aspf=r; rua=mailto:[email protected] Bounce (MAIL FROM) domain: bounce.example.com Header From domain: example.com DKIM d= domain: sel1.example.com Organizational domain for relaxed alignment: example.com
You get
No structural problems found in the three records. Record domain | example.com | The label used for this audit. SPF terms needing DNS | 3 of 10 | include, a, mx, ptr, exists and redirect are counted. Recursive lookups inside included records are unknowable here. SPF unresolved targets | include:mailer.example.net (not looked up) | Nothing is looked up. Each target is reported as seen.

Options

Public records
Supply the public record text and declared scenario. Do not paste account passwords or private signing keys.
Alignment mode
Strict alignment compares exact domains. Relaxed scenarios require the supported explicit organizational-domain inputs.

Supported inputs and limits

Offline record and scenario subset only. No DNS resolution, recursive SPF evaluation, DKIM message verification, deliverability or live authentication guarantee.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Missing lookup evidence remains unresolved

SPF includes and redirects can require other DNS records, which this page does not fetch. DKIM record structure does not verify a message signature. Relaxed alignment needs independently supplied organizational-domain information rather than a guessed suffix. Use unresolved findings to plan the real DNS and message checks.

Questions about Email Authentication Configuration Audit

Does it check my DNS?

No. Only supplied record text is reviewed.

Does a DKIM record mean a message passed?

No. Message-signature verification is a separate operation.

Can the page infer organizational domains?

No. Supply the supported domain information for relaxed-alignment scenarios.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem