SPF·DKIM·DMARC· DNSSEC·MX·12 blacklists
One domain, every check that matters, in seconds. You get a graded verdict. and the corrected record, ready to paste. No account, no card.
No domain handy? Run ·
Find yourself here
Your sequences stopped getting replies
Open rates fell off a cliff and nothing in the CRM changed. Usually DKIM on the sending subdomain, not the copy.
Someone is sending mail as you
Customers forward you invoices you never issued. Without an enforcing DMARC policy, nobody is told to stop it.
A bounce report says 550 5.7.515
Outlook is rejecting you outright, not filing you in junk. This one has a deadline attached and it already passed.
An engineer said "check your DNS"
And left. You need the exact record to paste and someone to tell you which registrar field it goes in.
You manage domains for clients
Fifteen of them, each with a different CRM, and no way to see which ones are quietly broken this morning.
The part nobody else checks
Your CRM needs its own records, its own DKIM selectors, its own SPF include, its own sending subdomain. Generic checkers say your domain is fine while your sequences land in spam. We check the CRM, by name, against its published spec.
What you actually get
01 · The rewrite engine
Every other checker returns a verdict and leaves you to draft the fix. Ours parses what is published, works out what it should say, and hands you the corrected line with a copy button. Malformed syntax, missing tags, wrong alignment mode, over-limit lookups, all repaired, not just flagged.
11 DNS lookups → 8. Flattened two nested includes, replaced ?all with ~all.
02 · CRM verifier
Point it at HubSpot and it looks for the hs1 and hs2 selectors on the sending subdomain, confirms the SPF include resolves, and checks alignment survives the CNAME chain. Six CRMs, each with its own rulebook. Upload a screenshot of your CRM's DNS panel and it reads the records straight off the image.
The sending subdomain is unresolved. HubSpot mail is sending unsigned.
03 · The report
Every scan exports to PDF or PNG with the findings, the corrected records and the reasoning. On Team and above the report carries your brand, your logo, your colours, PREPARED BY on every page, so agencies can send it to a client without ours appearing anywhere.
Page 1 of 6 · corrected records and per-item reasoning follow.
Free · no account
No trial timer, no credit card, no "3 checks remaining". Paid plans add monitoring, history, branding and the API, the checks themselves stay free.
Why now, specifically
Every date below has passed. Mail that fails these checks is being junked or refused today, not at some future deadline.
| Rule | What it requires | Applies to | In force |
|---|---|---|---|
| Microsoft | SPF and DKIM must pass, DMARC at minimum p=none, aligned. Failures return 550 5.7.515. | Over 5,000/day to outlook.com, hotmail.com, live.com | 5 May 2025 |
| SPF or DKIM aligned, DMARC published, one-click unsubscribe, spam rate under 0.3%. | Over 5,000/day to Gmail | Feb 2024 | |
| Yahoo | Matching requirements to Google's, applied across Yahoo and AOL mailboxes. | Bulk senders | Feb 2024 |
| PCI DSS 4.0 | Anti-phishing controls on domains handling cardholder data. DMARC named in guidance. | Anyone processing card payments | Mar 2025 |
| DORA | ICT risk management for financial entities, including email-borne threat controls. | EU financial institutions | Jan 2025 |
| NIS 2 | Cybersecurity baseline across essential and important sectors. | EU, multiple sectors | Oct 2024 |
Dates are the enforcement dates published by each provider or regulator. Scope varies. check the source before treating any row as legal advice.
Privacy by design
Most tools that claim "we hash your emails" use a bare SHA-256. That is reversible: the space of real email addresses is small and guessable, so a dictionary attack recovers the original in seconds.
Every third-party address you check is HMAC-SHA256 hashed at entry with a server-side secret key before it touches the database. Without the key the fingerprint is inert. and the key never leaves the worker.
The stored fingerprint is enough to remember that this address bounced last month. It is not enough to email them, sell them, or work out who they are.
Your own account email is stored in plaintext, you consented to that at signup. The separation is enforced in the schema, not by policy. How we protect checked emails →
Honest comparison
| At roughly $99/month | EmailSheriff Team | PowerDMARC | EasyDMARC |
|---|---|---|---|
| Domains included | 50 | 1–5 | 1–10 |
| Corrected record supplied | Yes | No | No |
| CRM-specific DNS check | 6 CRMs | None | None |
| Email list validation | Included | None | None |
| White-label reports | Yes | Add-on | Higher tier |
| Account needed to run a check | No | No | No |
Competitor figures are taken from published pricing pages and change often, verify before relying on them. We do not compete on price; we compete on what the scan hands back.
Before you ask
Really free. Every scan on this page runs without an account and without a counter. Paid plans add continuous monitoring, scan history, white-label reports and API access, the checks themselves are not metered.
The domain and the result, so repeat scans are fast. If you upload a list to the Email List Verifier, every third-party address is SHA-256 hashed before it touches the database, we never hold the plaintext of someone who did not sign up with us. Your own account email is stored in plaintext because you consented at signup. Details in the privacy policy.
Because DMARC passing on your root domain says nothing about the subdomain your CRM sends from. HubSpot, Mailchimp and the rest send from a delegated subdomain with their own DKIM selectors. That subdomain can be entirely unsigned while your main domain grades A. Generic checkers never look.
p=reject?You can, and it is the wrong first move for most domains. Reject bounces anything that
fails alignment, including legitimate mail from a service you forgot about. Publish
p=quarantine with a rua address, read the reports for about thirty days, fix
what surfaces, then tighten.
MxToolbox tells you what is published. We tell you what should be published and hand it to you formatted. On top of that: CRM-specific verification, email list validation and branded PDF export, none of which they do.
Cards and PayPal worldwide, in USD. In India we also take UPI and netbanking and issue a GST invoice. Your region is detected automatically and you can override it at checkout if the detection is wrong.
No account, no card, no counter. If something is broken you will have the corrected record before you finish reading this sentence.