COMPLIMENTARY TOOL  //  check any domain's SPF, DKIM, DMARC and MX in seconds Apply
Complimentary deliverability checker

Is your domain inbox ready?

Enter a domain. We check the records that decide whether receivers trust your mail: MX, SPF with its 10-lookup audit, DMARC policy, DKIM selectors, MTA-STS, TLS-RPT and BIMI. Queries go straight from your browser to public DNS, nothing is stored, no signup.

DNS queries run from YOUR browser via Cloudflare and Google DNS-over-HTTPS. ReplyLead receives and stores nothing.  

The domain report appears here.

Records are step one. Reputation is the war.

We build and warm the whole sending infrastructure for clients, domains, mailboxes, ramp-up and monitoring, and get paid on the revenue we help close.

How we run deliverability Apply to work with us

Questions about email authentication

What do SPF, DKIM and DMARC actually do?

SPF lists which servers may send mail for your domain. DKIM cryptographically signs each message so receivers can verify it was not altered. DMARC tells receivers what to do when a message fails those checks, and where to send reports. Gmail and Yahoo require all three for bulk senders, and weigh them for everyone else.

Why does the SPF lookup count matter?

SPF allows at most 10 DNS lookups per check. Every include, a, mx, ptr, exists and redirect costs one, and includes count everything they include in turn. Past 10 the record returns a permanent error and receivers treat your mail as unauthenticated, which is a common silent deliverability killer.

What DMARC policy should a cold email domain use?

Start at p=none with a rua reporting address to observe, then move to quarantine and finally reject once legitimate mail passes alignment. A domain that never reaches an enforcing policy stays easy to spoof, and receivers score it accordingly.

Why can this tool not find my DKIM record?

DKIM records live at selector._domainkey.yourdomain, and the selector name is chosen by your email provider. This tool probes the common selectors used by Google Workspace, Microsoft 365, Zoho, SendGrid, Mailgun and others; if yours is custom, enter it in the selector field. Amazon SES uses three random selectors that cannot be guessed.

Why is there no blacklist check?

Honest answer: the major DNS blacklists refuse queries that arrive through public resolvers such as 1.1.1.1 or 8.8.8.8, which is exactly how a browser-based tool must query. A blacklist result produced that way would often be wrong, and a wrong all-clear is worse than no answer. Checking blacklists properly needs a dedicated resolver.

Does this tool store the domains I check?

No. The checks run in your browser and the DNS queries go directly from your browser to Cloudflare and Google public DNS over HTTPS. Nothing is sent to or stored by ReplyLead.

Will passing these checks get my cold email delivered?

Authentication is necessary but not sufficient. Placement also depends on domain age and reputation, volume ramp-up, list quality and recipient engagement. A perfectly authenticated domain that blasts a purchased list still ends up in spam.