69
/ 100
Good
google.com
● SPF○ DKIM● DMARC● MTA-STS● TLS-RPT○ BIMI
Last checked: 2026-04-25 · Permalink
Detailed Checks
SPF
PassedRecord
v=spf1 include:_spf.google.com ~allAll Mechanism~all
Includes_spf.google.com
DNS Lookups1
SPF uses '~all' (softfail) — unauthorized sends will be marked but not rejected.
Softfail is a safe starting point. For stronger protection, consider '-all' (hardfail) once you're confident all legitimate senders are included.
DKIM
MissingNo DKIM record found for any common selector.
DKIM signatures add a cryptographic seal to your outgoing emails. If you send email, set up DKIM with your ESP (email service provider) and publish the public key in DNS. Use the --selectors flag to check specific selectors.
DMARC
PassedPolicyreject
Reporting (rua)mailauth-reports@google.com
MTA-STS
PassedModeenforce
MX Patternssmtp.google.com, aspmx.l.google.com, *.aspmx.l.google.com
Max Age86400s
TLS-RPT
PassedReportingmailto:sts-reports@google.com
BIMI
MissingNo BIMI record found.
BIMI allows your brand logo to appear next to emails in supported clients. Publish a TXT record at default._bimi.<domain> with 'v=BIMI1; l=<logo_url>;'.
Check Your Own Domain's Email Deliverability
Get instant SPF, DKIM, DMARC, MTA-STS, TLS-RPT, and BIMI analysis for any domain — free.