COMPLIMENTARY TOOL  //  check any domain's SPF, DKIM, DMARC and MX in seconds Apply
Complimentary deliverability checker

Is your domain inbox ready?

Check public email DNS records: MX, SPF, DMARC, common DKIM selectors and optional transport or branding records. The result is a DNS checklist, not an inbox-placement test. It cannot verify a sent message’s authentication, sender reputation or delivery. Queries run from your browser through Cloudflare or Google DNS-over-HTTPS.

DNS queries run from YOUR browser via Cloudflare and Google DNS-over-HTTPS. The domain and selector are not included in ReplyLead’s tool-usage events.  

The domain report appears here.

Records are step one. Reputation is the war.

We build and warm the whole sending infrastructure for clients, domains, mailboxes, ramp-up and monitoring, and get paid on the revenue we help close.

How we run deliverability Apply to work with us

What this email deliverability test covers, and what it cannot

This tool reports records it finds in DNS. Its score uses an editorial weighting, not a receiver’s ranking or a measured probability of delivery. A published DKIM key does not prove messages are signed; DMARC policy does not prove alignment. The SPF count is an approximate record traversal, not a complete RFC evaluation for a particular sending IP. MTA-STS needs a valid HTTPS policy as well as DNS; TLS-RPT and BIMI also need more than a TXT record to work. Google’s sender requirements cover message-level and reputation checks beyond this tool. The SPF standard and MTA-STS standard describe the corresponding protocol requirements.

Questions about email authentication

What do SPF, DKIM and DMARC actually do?

SPF authorizes sending servers for an envelope domain. DKIM lets a receiver verify a message signature. DMARC evaluates alignment with the visible From domain and publishes policy and reporting information. This tool finds DNS records; it does not authenticate a message. Personal Gmail bulk-sender requirements include SPF, DKIM and DMARC, with p=none allowed.

Why does the SPF lookup count matter?

RFC 7208 limits the DNS-querying terms evaluated during an SPF check to ten, with additional processing limits. The result depends on the evaluation path and sending IP. This tool traverses published records approximately; its count is a review aid, not proof that a particular message will pass or fail SPF.

What DMARC policy should a cold email domain use?

Choose policy after identifying legitimate senders and checking alignment using message headers and reports. A monitoring policy can help collect evidence before enforcement. A published reject policy alone does not prove alignment or inbox placement, and changing policy without that evidence can disrupt legitimate mail.

Why can this tool not find my DKIM record?

DKIM records live at selector._domainkey.yourdomain, and the selector name is chosen by your email provider. This tool probes the common selectors used by Google Workspace, Microsoft 365, Zoho, SendGrid, Mailgun and others; if yours is custom, enter it in the selector field. Amazon SES uses three random selectors that cannot be guessed.

Why is there no blacklist check?

Honest answer: the major DNS blacklists refuse queries that arrive through public resolvers such as 1.1.1.1 or 8.8.8.8, which is exactly how a browser-based tool must query. A blacklist result produced that way would often be wrong, and a wrong all-clear is worse than no answer. Checking blacklists properly needs a dedicated resolver.

Does this tool store the domains I check?

No. The checks run in your browser and the DNS queries go directly from your browser to Cloudflare and Google public DNS over HTTPS. Nothing is sent to or stored by ReplyLead.

Will passing these checks get my cold email delivered?

Authentication is necessary but not sufficient. Placement also depends on domain age and reputation, volume ramp-up, list quality and recipient engagement. A perfectly authenticated domain that blasts a purchased list still ends up in spam.