Help
What the individual checks tell you.
- SPF
- Is the connecting IP allowed to send for the envelope sender domain? This can differ from the visible sender.
- DKIM
- Does each signature match the original message bytes and published key? Signatures are checked separately.
- DKIM Oversigning
- Does a valid signature also protect against adding another header with the same name? We compare occurrences in h= with actual header counts, including recommended absent fields.
- DMARC
- Does SPF or DKIM pass with an identity aligned to the visible From domain? Relaxed alignment and policy none are not automatically failures.
- TLS
- Was the final SMTP connection encrypted? Earlier hops are not verified by this observation.
- Reverse DNS
- Does a PTR name resolve back to the connecting IP?
- Received
- Received headers are untrusted claims about earlier hops. We flag future or reversed timestamps (with five minutes of tolerance), unparsed fields and hostname gaps. Aliases, internal routing and clock skew may explain these. X-Received and ARC alone are not suspicious. This check proves neither tampering nor spam; it does not verify ARC.
- DNSSEC
- Did an explicitly trusted resolver validate DNS answers? Unsigned, invalid and unknown are different states.
- Checks incomplete
- A timeout or missing evidence prevents a reliable conclusion. Try a new test; a technical failure is never treated as a pass.
Results remain available for 24 hours. Use synthetic content only. The service is not a mailbox and does not forward messages.