In force Outlook rejects unauthenticated bulk mail with 550 5.7.515. Google and Yahoo since 2024. See the rules →

SPF·DKIM·DMARC· DNSSEC·MX·12 blacklists

Every mailbox provider now reads your DNS.

One domain, every check that matters, in seconds. You get a graded verdict. and the corrected record, ready to paste. No account, no card.

Scan a domain free · unlimited

No domain handy? Run ·

Find yourself here

You are here because something stopped arriving.

Your sequences stopped getting replies

Open rates fell off a cliff and nothing in the CRM changed. Usually DKIM on the sending subdomain, not the copy.

Someone is sending mail as you

Customers forward you invoices you never issued. Without an enforcing DMARC policy, nobody is told to stop it.

A bounce report says 550 5.7.515

Outlook is rejecting you outright, not filing you in junk. This one has a deadline attached and it already passed.

An engineer said "check your DNS"

And left. You need the exact record to paste and someone to tell you which registrar field it goes in.

You manage domains for clients

Fifteen of them, each with a different CRM, and no way to see which ones are quietly broken this morning.

The part nobody else checks

A valid DMARC record and a broken HubSpot setup look identical to every other tool.

Your CRM needs its own records, its own DKIM selectors, its own SPF include, its own sending subdomain. Generic checkers say your domain is fine while your sequences land in spam. We check the CRM, by name, against its published spec.

What you actually get

Three things that are ours alone.

01 · The rewrite engine

We don't tell you the record is wrong. We write the right one.

Every other checker returns a verdict and leaves you to draft the fix. Ours parses what is published, works out what it should say, and hands you the corrected line with a copy button. Malformed syntax, missing tags, wrong alignment mode, over-limit lookups, all repaired, not just flagged.

emailsheriff.com/dns-checker
SPF · yourcompany.com 2 problems
Published v=spf1 include:_spf.google.com include:sendgrid.net include:mail.zendesk…
Corrected v=spf1 include:_spf.google.com include:sendgrid.net ~all

11 DNS lookups → 8. Flattened two nested includes, replaced ?all with ~all.

02 · CRM verifier

Checked against your CRM's own spec, not a generic template.

Point it at HubSpot and it looks for the hs1 and hs2 selectors on the sending subdomain, confirms the SPF include resolves, and checks alignment survives the CNAME chain. Six CRMs, each with its own rulebook. Upload a screenshot of your CRM's DNS panel and it reads the records straight off the image.

emailsheriff.com/crm-dns-verifier
HubSpot · 4 of 5 records correct B+
hs1hs1._domainkey → hs1.yourco.hs…
hs2hs2._domainkey → hs2.yourco.hs…
SPFinclude:_spf.hubspot.com present
Sendingemail.yourco.com, no CNAME

The sending subdomain is unresolved. HubSpot mail is sending unsigned.

03 · The report

A PDF you can hand to an engineer with your own logo on it.

Every scan exports to PDF or PNG with the findings, the corrected records and the reasoning. On Team and above the report carries your brand, your logo, your colours, PREPARED BY on every page, so agencies can send it to a client without ours appearing anywhere.

deliverability-report.pdf
Deliverability audit Prepared by your agency
GradeB+ · 7 of 9 checks passed
AuthSPF pass · DKIM 2048-bit · DMARC quarantine
RBLs0 listings across 12 blacklists
MTA-STSNo policy, mail can downgrade

Page 1 of 6 · corrected records and per-item reasoning follow.

Why now, specifically

These are not recommendations. They are already enforced.

Every date below has passed. Mail that fails these checks is being junked or refused today, not at some future deadline.

RuleWhat it requiresApplies toIn force
MicrosoftSPF and DKIM must pass, DMARC at minimum p=none, aligned. Failures return 550 5.7.515.Over 5,000/day to outlook.com, hotmail.com, live.com5 May 2025
GoogleSPF or DKIM aligned, DMARC published, one-click unsubscribe, spam rate under 0.3%.Over 5,000/day to GmailFeb 2024
YahooMatching requirements to Google's, applied across Yahoo and AOL mailboxes.Bulk sendersFeb 2024
PCI DSS 4.0Anti-phishing controls on domains handling cardholder data. DMARC named in guidance.Anyone processing card paymentsMar 2025
DORAICT risk management for financial entities, including email-borne threat controls.EU financial institutionsJan 2025
NIS 2Cybersecurity baseline across essential and important sectors.EU, multiple sectorsOct 2024

Dates are the enforcement dates published by each provider or regulator. Scope varies. check the source before treating any row as legal advice.

0
Free tools, no account
0
Blacklists swept
0
CRMs checked by name
$0
To run every check

Privacy by design

We run the audit on a fingerprint, never the address.

A plain hash is not privacy. Ours is keyed.

Most tools that claim "we hash your emails" use a bare SHA-256. That is reversible: the space of real email addresses is small and guessable, so a dictionary attack recovers the original in seconds.

Every third-party address you check is HMAC-SHA256 hashed at entry with a server-side secret key before it touches the database. Without the key the fingerprint is inert. and the key never leaves the worker.

Hashed at entry, in the same request that receives it
Your customers' addresses are never stored in plaintext
Nothing sold, nothing shared, no third-party validation partner
Record generators run entirely in your browser, nothing is sent at all
What you upload[email protected]
HMAC-SHA256 + server key
What we storea41f3a29fc8d329fea9c2f4a…

The stored fingerprint is enough to remember that this address bounced last month. It is not enough to email them, sell them, or work out who they are.

Your own account email is stored in plaintext, you consented to that at signup. The separation is enforced in the schema, not by policy. How we protect checked emails →

Honest comparison

Same checks as the legacy tools. Designed for this decade.

At roughly $99/monthEmailSheriff TeamPowerDMARCEasyDMARC
Domains included501–51–10
Corrected record suppliedYesNoNo
CRM-specific DNS check6 CRMsNoneNone
Email list validationIncludedNoneNone
White-label reportsYesAdd-onHigher tier
Account needed to run a checkNoNoNo

Competitor figures are taken from published pricing pages and change often, verify before relying on them. We do not compete on price; we compete on what the scan hands back.

Before you ask

Questions people send us.

Is it really free, or is there a check limit?

Really free. Every scan on this page runs without an account and without a counter. Paid plans add continuous monitoring, scan history, white-label reports and API access, the checks themselves are not metered.

What do you store when I scan a domain?

The domain and the result, so repeat scans are fast. If you upload a list to the Email List Verifier, every third-party address is SHA-256 hashed before it touches the database, we never hold the plaintext of someone who did not sign up with us. Your own account email is stored in plaintext because you consented at signup. Details in the privacy policy.

Why does the CRM check matter if my DMARC already passes?

Because DMARC passing on your root domain says nothing about the subdomain your CRM sends from. HubSpot, Mailchimp and the rest send from a delegated subdomain with their own DKIM selectors. That subdomain can be entirely unsigned while your main domain grades A. Generic checkers never look.

Can I go straight to p=reject?

You can, and it is the wrong first move for most domains. Reject bounces anything that fails alignment, including legitimate mail from a service you forgot about. Publish p=quarantine with a rua address, read the reports for about thirty days, fix what surfaces, then tighten.

How is this different from MxToolbox?

MxToolbox tells you what is published. We tell you what should be published and hand it to you formatted. On top of that: CRM-specific verification, email list validation and branded PDF export, none of which they do.

Which payment methods do you take?

Cards and PayPal worldwide, in USD. In India we also take UPI and netbanking and issue a GST invoice. Your region is detected automatically and you can override it at checkout if the detection is wrong.

Scan the domain. It takes five seconds.

No account, no card, no counter. If something is broken you will have the corrected record before you finish reading this sentence.

See pricing