Email Authentication Analyzer
Analyse a domain's full email authentication posture — SPF, DKIM, DMARC, MTA-STS and BIMI — in one scan with a 0-100 score. Free, using live DNS.
Analyse email authentication
Enter a domain to check SPF, DKIM, DMARC, MTA-STS and BIMI in one scan.
What this analyzer checks
Common use cases
- 1A one-click audit of a domain's email security
- 2Finding the biggest authentication gap to fix first
- 3Benchmarking a domain before onboarding
- 4Checking your setup after DNS changes
- 5Producing a posture score for a report
- 6Reviewing a domain you are acquiring
Related tools
About email authentication
Modern email security rests on layers: SPF authorises sending servers, DKIM signs messages, and DMARC ties them together and tells receivers what to do on failure. MTA-STS enforces TLS in transit, and BIMI displays your logo once the rest is in place.
This analyzer checks all five over live DNS and scores your posture so you know exactly what to fix and in what order. Start with SPF and DKIM, reach DMARC enforcement, then add MTA-STS and BIMI.
More Free Tools Where This Came From
This utility is one of dozens of free, no-login tools for DNS, email, SEO and developers — all instant and private.
HostCloud.in · Pune, India · Serving 34,987+ Websites Since 2020
Got Questions? We Have Answers.
What does the analyzer check?
In one scan it checks SPF, DKIM (common selectors), DMARC, MTA-STS and BIMI over live DNS, then gives a weighted 0-100 posture score with prioritised fixes.
How is the score calculated?
Each layer is weighted by impact — DMARC and SPF most, then DKIM and MTA-STS, then BIMI — and combined into a single posture score out of 100.
Why does DKIM show as missing?
DKIM selectors cannot be listed from DNS, so the analyzer probes common ones. A custom selector may exist even if none are found — verify with the DKIM Record Checker.
What should I fix first?
Start with SPF and DKIM, then reach DMARC enforcement, then add MTA-STS and BIMI. The analyzer orders the gaps by impact.
Does this use live DNS?
Yes. Every record is resolved over DNS-over-HTTPS at the moment you run the scan — no cached data.
Is this a replacement for the individual checkers?
It is a fast overview. For deep detail on one layer, use the dedicated SPF, DKIM, DMARC or BIMI checker.
