Tools
Test your domain. Then test a message.
Two tools, both free, neither needs an account. The domain scan reads what your DNS declares. The message check verifies what a real message actually carries.
Every check, by record
Looking for one specific check? Each of these is part of the domain scan. They are listed so you can find the one you came for, not because they are separate pages.
Domain scan
OpenSPF · DKIM · DMARC · MX · MTA-STS · TLS-RPT · BIMI · DNSSEC · CAA · DANE
Reads all twelve record types in one lookup, follows every SPF include, and names each service authorised to send for you.
Message check
OpenDKIM signature · SPF · DMARC alignment
Send a real message to a one-time address. Cryptographic verification against the actual signature, SPF against the IP that connected, and whether the two align.
SPF lookup counter
In the domain scanSPF
Expands every include and counts DNS lookups against the hard limit of 10. Names the include to drop when you are over. Never flattens.
DKIM selector check
In the domain scanDKIM
Checks each recognised service against its documented default selectors, and any custom selector you supply.
DMARC record check
In the domain scanDMARC
Policy, subdomain policy, alignment mode, percentage, and whether the addresses in your rua and ruf tags can actually receive reports.
BIMI check
In the domain scanBIMI · VMC
Whether a BIMI record exists, whether it names a Verified Mark Certificate, and whether your DMARC policy is strict enough for any of it to display.
MX and transport check
In the domain scanMX · A/AAAA · PTR
Hosts, priorities, who operates them, what they resolve to, and whether reverse DNS forward-confirms back to the same address. Live STARTTLS negotiation is not part of the scan yet.
MTA-STS check
In the domain scanMTA-STS
Fetches the policy file and validates it against live DNS. A policy naming hosts your MX no longer uses is how inbound mail stops silently.
TLS-RPT check
In the domain scanTLS-RPT
Validates the record and confirms the reporting address can receive. This is the closest thing to a report about your own mail servers.
DNSSEC, CAA and DANE
In the domain scanDNSSEC · CAA · DANE/TLSA
Whether the zone is signed and the chain actually validates, which authorities may issue certificates for you, and whether any TLSA records you publish are protected by DNSSEC or merely decorative.
Blocklist lookup
ComingDNSBL
Your sending IPs across the major public blocklists. This runs against the addresses seen in your aggregate reports, so it needs a monitored domain. It is not part of the one-off scan.
Our own posture
OpenEverything above
Every check we run, run against emailsecurity.pro and published hourly, whether the result flatters us or not.
Checks marked in the domain scan are not separate pages. The scan runs them together, because the useful findings are the ones that only appear when records are compared against each other.
What a single lookup cannot tell you
A scan is a photograph of your DNS this second. It cannot tell you who has been sending as you, from where, or whether it passed, because that information only arrives in reports, over days, from the mailbox providers themselves.
That is what an account adds: continuous aggregate and forensic report ingestion, sender classification, alerting that stays quiet about forwarding, hosted MTA-STS, and a health score you can watch drift.
Start monitoring, free for one domainUsing custom DKIM selectors?
Every service publishes a recommended selector, but nobody is obliged to use it. Signet checks the documented defaults for each service it recognises, and if they are not there it says so plainly rather than declaring a failure.
The domain scan takes your own selectors too. Open Using custom DKIM selectors? under the domain field and they will be verified alongside the defaults.