Is your email set up
to reach the inbox?
Check SPF, DKIM, DMARC and blacklists in seconds. Free, no signup. Google, Yahoo and Microsoft now reject bulk mail that fails authentication, so a broken record means spam, silently. Type a domain and get a plain-English verdict with concrete fixes.
What we check
- SPF. Record present, mechanisms valid, DNS lookup count under the RFC 10-lookup limit, qualifier strictness.
- DKIM. We probe 30+ common selectors (default, google, k1, selector1, amazonses, etc.) and report any keys found.
- DMARC. Policy, percentage, alignment modes, reporting addresses. Falls back to the organisational domain per RFC 7489.
- MX. Records present, priorities, reverse DNS.
- BIMI. Brand indicator setup readiness (needs DMARC at quarantine/reject first).
- MTA-STS + TLS-RPT. Modern transport security policies.
- Blacklists. Spamhaus, Barracuda, SORBS, CBL, and 11 more.
When should I run this?
- Before any cold outreach campaign.
- After any DNS change (SPF edit, DKIM key rotation, new sending platform).
- When deliverability is mysteriously dropping.
- When you've migrated to a new email provider.
- Before you scale up sends. If the setup is broken, fix it first. Bounce rates over 2-3% get you filtered.
FAQ
What does the domain check tell me?
It runs a full deliverability audit: SPF record validity (and DNS lookup count, capped at 10 by RFC 7208), DKIM keys across 30+ common selectors, DMARC policy and alignment modes, MX records, BIMI readiness, MTA-STS, TLS-RPT, and a blacklist sweep across 15 major DNSBLs.
Why does my SPF say "soft fail"? Is that bad?
Soft fail (~all) means receivers should *suggest* rejection but may still deliver. It's the safer default during rollout. Once you're confident every legitimate sender is in your record, harden to hard fail (-all).
My DKIM check says no key found. But I send via Gmail/Outlook?
Google Workspace and Microsoft 365 sign messages by default with their own domain (e.g. gappssmtp.com), not yours. The signature is valid, but it doesn't align with your From address, so DMARC fails. You need to publish a DKIM key on your own domain.
My domain has DMARC at p=none. Should I change it?
Once you've been collecting aggregate reports for 2-4 weeks and confirmed no legitimate traffic is failing, escalate to p=quarantine. Then p=reject. Without enforcement, spoofers can impersonate your domain freely.
How often should I check my domain?
After any DNS change, before any outbound campaign, and continuously if you can. DNS records break silently. That's why Conductor re-checks your deliverability before every send it makes for you.
Is the data shared?
The domain you check is logged for rate-limiting. The verdict is not shared publicly unless you explicitly create a shareable URL. We never sell data.
BEYOND THE CHECK
Checking is step one. Landing is the job.
Conductor connects to your inbox, fixes your authentication, warms the mailbox, and runs your cold sequences with a deliverability gate on every send. Built so your email lands without burning the domain.
Start free →