Mailcheck SMTP · SPF · DKIM · DMARC

Help

What the individual checks tell you.

SPF
Is the connecting IP allowed to send for the envelope sender domain? This can differ from the visible sender.
DKIM
Does each signature match the original message bytes and published key? Signatures are checked separately.
DKIM Oversigning
Does a valid signature also protect against adding another header with the same name? We compare occurrences in h= with actual header counts, including recommended absent fields.
DMARC
Does SPF or DKIM pass with an identity aligned to the visible From domain? Relaxed alignment and policy none are not automatically failures.
TLS
Was the final SMTP connection encrypted? Earlier hops are not verified by this observation.
Reverse DNS
Does a PTR name resolve back to the connecting IP?
Received
Received headers are untrusted claims about earlier hops. We flag future or reversed timestamps (with five minutes of tolerance), unparsed fields and hostname gaps. Aliases, internal routing and clock skew may explain these. X-Received and ARC alone are not suspicious. This check proves neither tampering nor spam; it does not verify ARC.
DNSSEC
Did an explicitly trusted resolver validate DNS answers? Unsigned, invalid and unknown are different states.
Checks incomplete
A timeout or missing evidence prevents a reliable conclusion. Try a new test; a technical failure is never treated as a pass.

Results remain available for 24 hours. Use synthetic content only. The service is not a mailbox and does not forward messages.

Start a new test