how to verify a domain's SPF DKIM DMARC setup quickly
Shows the fastest way to check a sending domain's SPF, DKIM, and DMARC records with dig and free lookup tools, and how to read the results. Use when verification emails are not arriving or when setting up a new sending domain; not for debugging mailbox-side spam filters.
TL;DR
Missing or broken SPF, DKIM, or DMARC is the most common cause of verification emails landing in spam or vanishing. The check takes two minutes and tells you exactly which record is missing. Works for any domain you control or are auditing.
The query
how to verify a domain's SPF DKIM DMARC setup quicklyUse this when
- Verification or transactional emails are not arriving reliably.
- You control or audit the sending domain's DNS.
- You need a two-minute check before deeper deliverability work.
Not for
- The emails arrive fine and you are just curious (check anyway; it is cheap, but it is not urgent).
- The domain is not yours and you cannot change its DNS (the check still informs you, but you cannot fix it).
- The problem is a mailbox-side filter rule (fix the filter, not DNS).
Steps
- Query the TXT records: dig TXT yourdomain.com for SPF and dig TXT _dmarc.yourdomain.com for DMARC.
Expected output: TXT records showing an SPF policy and a DMARC policy, or a clear absence of one.
- Check DKIM with the selector your provider gave you: dig TXT [selector]._domainkey.yourdomain.com.
Expected output: A DKIM public key record, confirming the provider's signing is published.
- Send a test email to a checker like mail-tester.com and read the authentication results.
Expected output: A scorecard showing SPF, DKIM, and DMARC all passing on a real message.
- Fix the missing record in DNS, wait for propagation, and re-test.
Expected output: All three checks green on the second pass.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst0vrQAVBBSuttYWBLQ16Dg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.