🔐 DNS Security Checker

Enter a domain to analyze its DNS-based security configuration: SPF, DMARC, DKIM (with an optional selector), DNSSEC, CAA, MX, and NS. Each finding is explained in plain language.

Input

Results

How It Works

The tool reuses this site's DNS Lookup to retrieve the relevant records, then analyzes them. SPF: the mechanisms (include, a, mx, ip4, ip6, all) and final policy are identified, and risky setups such as +all, multiple SPF records, or too many DNS-lookup mechanisms are flagged. DMARC: the policy (none, quarantine, reject) and tags are read from _dmarc.<domain>. DKIM: if you supply a selector, the public-key record at <selector>._domainkey.<domain> is shown. DNSSEC: DS and DNSKEY records are checked. CAA: the certificate authorities permitted to issue certificates for the domain are listed.

Scope and limits: this is a configuration analysis, not full compliance validation. SPF include chains are not recursively resolved, DKIM email signatures are not verified (that requires an actual message), and the presence of DNSSEC records does not prove the chain of trust is valid.

Examples & Common Use Cases

  • Confirm a domain has an enforcing DMARC policy rather than monitoring-only.
  • Find an SPF record ending in +all or exceeding the lookup limit.
  • Check that a DKIM selector your mail provider gave you is actually published.