Run a live DNS lookup on any domain's SPF, DKIM, DMARC, and MX records and see in seconds which ones Gmail and Outlook will trust. No signup, and unlike inbox-placement testers, no test email to send.
Domain reputation is the trust score Gmail, Outlook, and other providers assign your sending domain based on authentication, sending history, bounce and complaint rates, and recipient engagement. It isn't one number you can look up — it's an internal score each provider keeps and rarely exposes directly.
Authentication is the part of that picture you can check right now, which is what this tool does: a broken or missing SPF, DKIM, or DMARC record is one of the fastest ways to tank a domain's reputation, because it signals to receiving servers that mail claiming to be from you can't be verified. Fixing authentication won't fix a reputation problem caused by sending history or engagement, but it removes one of the most common causes outright.
For the full picture — including what to do if authentication passes but you're still landing in spam — see why domain reputation drops and how to recover it.
Lists which mail servers are allowed to send email on behalf of your domain. Without it, a receiving server has no way to confirm your ESP or SMTP relay is authorized to send as you, which makes spam-folder placement or outright rejection more likely.
Attaches a cryptographic signature to every outgoing message so the receiving server can verify it wasn't altered in transit and genuinely originated from your domain's mail system.
Tells receiving servers what to do when a message fails SPF or DKIM — quarantine it, reject it, or let it through anyway — and where to send reports about who is currently sending mail as your domain.
Points to the servers responsible for receiving mail for your domain. A missing or misconfigured MX record can block incoming replies even when your outbound sending setup is otherwise fine.
Most "deliverability checkers" work by having you send a real email to a seed address, then grading whatever arrives. That's useful for catching spam-trigger words or a bad sending IP, but it says nothing about whether your authentication records are configured correctly, and it requires an extra step every time you want to re-check.
This tool skips that: enter a domain, and it queries the SPF, DKIM, DMARC, and MX DNS records directly, the same way Gmail and Outlook do at the moment of delivery. The trade-off is honesty, not magic — a DNS lookup can't give you a spam score or an inbox-placement percentage. Use this one first to rule authentication in or out as the cause, then pair it with a send-based tester if you need placement data too.
Passing all four checks is necessary but not sufficient for inbox placement — sender reputation and domain age matter just as much, which is why InboxPulse pairs daily authentication monitoring with Warmflow's automated warmup instead of treating a passing DNS check as the finish line.
It looks up your domain's SPF, DKIM, DMARC, and MX DNS records and tells you whether each one passes, is missing, or has an error — the same checks that determine whether Gmail and Outlook trust your sending domain.
It checks the DNS authentication records — SPF, DKIM, DMARC, MX — that are one input into your domain reputation, but it doesn't compute a single reputation score. No free DNS-lookup tool honestly can: reputation also depends on sending history, bounce and complaint rates, and engagement, which live at Gmail and Microsoft, not in DNS. Google's own Postmaster Tools is the closest thing to a real reputation score, and it only works for domains sending through Gmail/Workspace recipients in volume.
There's no universal numeric score you can look up for any domain. The closest practical proxy: pass all four checks here, verify you're not on a major blocklist (MXToolbox or MultiRBL), and if you send through Google Workspace, check Postmaster Tools' domain reputation graph (High/Medium/Low) directly. A domain with clean authentication, no blocklist hits, and steady engagement is in good shape even without a single number to point to.
Yes. There's no signup, no email required, and results are instant, though checks are rate-limited to prevent abuse.
DKIM selectors are chosen by whoever set up your sending domain, and there's no public way to discover the exact selector without checking your sent mail headers. This tool checks the most common selectors used by major email providers and ESPs — if your provider uses a custom selector, it may not be detected here even though DKIM is correctly configured.
Authentication passing means receiving servers trust that a message really came from your domain — it doesn't guarantee inbox placement. Sender reputation, engagement history, content, and how new the domain is all factor in separately. A domain with perfect SPF, DKIM, and DMARC can still land in spam if it's brand new or sending too much volume too fast; that's what email warmup is for.
Usually minutes to a few hours, depending on your DNS provider's TTL setting, though it can occasionally take up to 24-48 hours. If a fix isn't reflecting yet, wait for your TTL to expire and re-run the check.
Yes, if you're sending from a custom domain (you@yourcompany.com) rather than a free @gmail.com or @outlook.com address. Google Workspace and Microsoft 365 don't add these DNS records to your domain automatically — you still have to configure them yourself.
Each failing check includes a plain-English note on what's missing. For a full walkthrough of deliverability fundamentals, see our deliverability guide.
Passing SPF, DKIM, DMARC and MX today is the baseline, not the finish. The records that pass this check are the same ones that silently break during a DNS edit or a provider migration.
Warmerly re-verifies them daily on every connected domain, alongside spam rate and blocklist status, and tells you which one changed when something does.

InboxPulse checks SPF, DKIM, DMARC, and MX every day and alerts you the moment something breaks — plus Warmflow's automated warmup to build the reputation these records alone can't.