Email domain health check

Enter a domain and every email-authentication record is looked up and validated at once, along with the blacklists that matter. You get a score out of 100 and a short list of what to fix first. Free, no sign-up, nothing stored.

Leave the selector blank and about forty common ones are tried. Results link straight to each record's own checker.

How it works

What the score is made of

Mailbox providers decide where your mail lands from a stack of signals, and the first layer is whether your domain proves its mail is really yours. Gmail and Yahoo (since 2024) and Outlook.com (since 2025) require bulk senders to publish SPF, sign with DKIM and run DMARC. Miss one and mail is junked or refused, however good the content is.

This check reads all of those records in parallel and weights them by how much they affect delivery: DMARC 25 points, SPF and DKIM 20 each, blacklists 15, and 5 each for MX, MTA-STS, TLS-RPT and BIMI. A warning earns partial credit; optional records you have not set up earn none, but never count as failures.

SPF · 20

Is there exactly one v=spf1 record, does it stay within the 10-DNS-lookup limit, and does it end in ~all or -all?

DKIM · 20

Is a public key published for the selectors your providers sign with, and is it at least 1024 bits (2048 recommended)?

DMARC · 25

Is there a policy at _dmarc, is it enforced (quarantine or reject), and do aggregate reports go somewhere that accepts them?

Blacklists · 15

Is the domain on a domain blacklist, and are its mail servers on IP blacklists? Lists that refuse public lookups are flagged, never guessed.

MX · 5

Does the domain accept mail, and does every MX host resolve? Replies and bounces need somewhere to go.

MTA-STS, TLS-RPT, BIMI · 5 each

Optional hardening: forced TLS for inbound mail, reports when TLS fails, and a verified logo in the inbox.

FAQ

Common questions.

What is a good score?

90 or above means the domain meets every current mailbox-provider requirement and has most of the optional hardening. 70–89 usually means DMARC is still at p=none or an optional record is missing. Below 70, something required is missing or broken, and it is costing you delivery.

Why does DKIM say no key was found when we do sign mail?

DNS cannot list a domain's DKIM keys; you have to know the selector. The check tries about forty common ones. If your platform uses its own, open a message you sent, find the s= value in its DKIM-Signature header, and enter it as the selector.

Which IPs are checked against blacklists?

The addresses of the domain's MX hosts, its inbound servers. The servers that send your mail can be different. For those, run the IP blacklist checker on the IP in the first Received header of a message you sent.

Is anything stored?

No. The DNS lookups run from your browser over DNS-over-HTTPS. Only the MTA-STS policy file and BIMI logo, which browsers cannot fetch cross-site, go through our server, and nothing about the check is kept.

For agents and pipelines

The same check, as an API and an MCP tool.

Point an MCP client (Claude, Cursor, any agent) at https://powerline.ai/mcp and call check_domain, or hit the JSON endpoint directly. No key, no account.

domain-check.sh
curl "https://powerline.ai/api/tools/domain-check?domain=example.com"
More free tools

Keep going.

SPF Checker

Validate the SPF record, follow every include, and count DNS lookups against the limit of 10.

DMARC Checker

Read the DMARC policy, alignment and reporting tags, and check that report addresses will accept reports.

DKIM Checker

Find the DKIM public key for a selector (or auto-detect common ones) and check its size and flags.

Domain Blacklist Checker

Check whether a domain, or the domain of an email address, is on a domain or URI blacklist.

Inbox Preview

See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.

All email tools