Enter a domain and every email-authentication record is looked up and validated at once, along with the blacklists that matter. You get a score out of 100 and a short list of what to fix first. Free, no sign-up, nothing stored.
Mailbox providers decide where your mail lands from a stack of signals, and the first layer is whether your domain proves its mail is really yours. Gmail and Yahoo (since 2024) and Outlook.com (since 2025) require bulk senders to publish SPF, sign with DKIM and run DMARC. Miss one and mail is junked or refused, however good the content is.
This check reads all of those records in parallel and weights them by how much they affect delivery: DMARC 25 points, SPF and DKIM 20 each, blacklists 15, and 5 each for MX, MTA-STS, TLS-RPT and BIMI. A warning earns partial credit; optional records you have not set up earn none, but never count as failures.
Is there exactly one v=spf1 record, does it stay within the 10-DNS-lookup limit, and does it end in ~all or -all?
Is a public key published for the selectors your providers sign with, and is it at least 1024 bits (2048 recommended)?
Is there a policy at _dmarc, is it enforced (quarantine or reject), and do aggregate reports go somewhere that accepts them?
Is the domain on a domain blacklist, and are its mail servers on IP blacklists? Lists that refuse public lookups are flagged, never guessed.
Does the domain accept mail, and does every MX host resolve? Replies and bounces need somewhere to go.
Optional hardening: forced TLS for inbound mail, reports when TLS fails, and a verified logo in the inbox.
90 or above means the domain meets every current mailbox-provider requirement and has most of the optional hardening. 70–89 usually means DMARC is still at p=none or an optional record is missing. Below 70, something required is missing or broken, and it is costing you delivery.
DNS cannot list a domain's DKIM keys; you have to know the selector. The check tries about forty common ones. If your platform uses its own, open a message you sent, find the s= value in its DKIM-Signature header, and enter it as the selector.
The addresses of the domain's MX hosts, its inbound servers. The servers that send your mail can be different. For those, run the IP blacklist checker on the IP in the first Received header of a message you sent.
No. The DNS lookups run from your browser over DNS-over-HTTPS. Only the MTA-STS policy file and BIMI logo, which browsers cannot fetch cross-site, go through our server, and nothing about the check is kept.
Point an MCP client (Claude, Cursor, any agent) at https://powerline.ai/mcp and call check_domain, or hit the JSON endpoint directly. No key, no account.
curl "https://powerline.ai/api/tools/domain-check?domain=example.com"
Validate the SPF record, follow every include, and count DNS lookups against the limit of 10.
Read the DMARC policy, alignment and reporting tags, and check that report addresses will accept reports.
Find the DKIM public key for a selector (or auto-detect common ones) and check its size and flags.
Check whether a domain, or the domain of an email address, is on a domain or URI blacklist.
See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.