Email domain health check
One check for everything a receiving server looks up about a sending domain. Each problem comes with what it means and a link to the fix.
What this checks
- SPF: one valid record, at most 10 DNS lookups, no more than two void lookups. The SPF checker shows the full include tree.
- DKIM: a public key at your selector, or at one of eight common selectors, that is not revoked and not a 1024-bit RSA key.
- DMARC: a record with a policy and a reporting address. The DMARC checker covers it on its own.
- BIMI: if published, a valid logo URL, a certificate, and DMARC strict enough for receivers to honor it.
- MX: somewhere for replies and bounces to go.
- Reverse DNS: PTR records on your MX hosts and on IPs listed in SPF that resolve back to the same address.
For the order a receiver runs these checks in, and why alignment is the one that fails, read how email authentication works.
Questions
Why can’t the check find my DKIM key?
DNS has no way to list selectors, so the check tries eight common ones. Open a message you sent, find the DKIM-Signature header, and enter the value of its s= tag as the selector.
Which IP addresses does the reverse DNS check test?
The first two MX hosts and up to three single IPv4 addresses listed directly in your SPF record. Addresses behind an include belong to your email provider, who maintains their reverse DNS.
Is my result stored or shared?
The result URL contains the domain, so anyone with the link can run the same check again. Results are cached for five minutes. Pharos keeps no list of checked domains, though Cloudflare’s request logs record page addresses, including a shared result link, for up to seven days.