Email deliverability checker
Look up your domain's SPF, DKIM and DMARC DNS records instantly. See exactly which authentication protocols are configured and whether they are set up correctly for reliable email delivery.
Enter a domain name and press Check Records to analyse your email authentication records.
Email authentication is what tells Gmail, Outlook and Yahoo that a message claiming to be from your domain actually came from you. Without SPF, DKIM and DMARC records, your legitimate emails land in spam — or get blocked entirely.
What the records do
SPF (Sender Policy Framework) publishes a list of IP addresses authorised to send mail for your domain. A typical SPF record looks like v=spf1 include:_spf.google.com ~all. Without SPF, anyone can forge your domain. If your SPF record has a syntax error or an include: that exceeds the ten-lookup limit, it fails silently and mail gets rejected.
DKIM (DomainKeys Identified Mail) adds a digital signature to outgoing messages. The receiving server looks up your public key at a DNS record like google._domainkey.yourdomain.com. DKIM is set up inside your email platform — Google Workspace, Microsoft 365, or your mail server — which gives you the DNS value to publish.
DMARC (Domain-based Message Authentication, Reporting & Conformance) tells receivers what to do when SPF or DKIM fail: none (monitor only), quarantine (spam) or reject (block). DMARC also sends you aggregate XML reports showing who is sending mail as your domain, which is essential for detecting email spoofing and phishing.
Why deliverability matters for Bahrain businesses
In the GCC, where email is still the primary business communication channel, poor deliverability costs real revenue. A bank confirmation, a proposal follow-up or an invoice that lands in spam may never be seen. With DMARC reporting, you can identify unauthorised senders and tighten your policy over time from p=none to p=reject as you validate legitimate traffic.
Frequently asked questions
SPF is the foundation — it lists which servers can send mail for your domain. DMARC builds on both SPF and DKIM to tell receivers what to do with unauthenticated mail.
No. DNS only allows one SPF record per domain. If you have more than one, all SPF checks will fail.
Most DNS providers propagate changes within minutes, but some DNS resolvers cache records for up to 24 hours. Check back after a few hours to confirm propagation.
Fix your email deliverability
Our team can audit your current DNS records, set up SPF/DKIM/DMARC correctly and monitor your DMARC reports.
Or message us on WhatsApp — replies within business hours.