Balou Tools

SPF, DKIM & DMARC Check

Analyze email authentication, find missing or risky DNS records and improve deliverability and spoofing protection.

Guide & best practices

SPF, DKIM & DMARC Check

Analyze email authentication, find missing or risky DNS records and improve deliverability and spoofing protection.

What are SPF/DKIM/DMARC?

SPF defines allowed sending servers, DKIM signs messages and DMARC tells receivers how to handle messages that fail alignment.

SPF 10 lookup limit

SPF allows at most ten DNS lookups. Too many include, a, mx or redirect mechanisms can make SPF fail.

Finding DKIM selectors

DKIM keys live under selector._domainkey.example.com. Common selectors include default, google, selector1, selector2 and k1.

Setting the right DMARC policy

Start with p=none and reporting, validate all legitimate senders and then move gradually to quarantine or reject.

Frequently asked questions

What is the SPF 10 lookup limit?

RFC 7208 limits SPF evaluation to ten DNS lookups. Exceeding it can cause a permanent SPF error.

How do I find my DKIM selector?

Check your mail provider admin UI or the DKIM-Signature header of a sent message.

What does p=reject mean?

p=reject is the strictest DMARC policy and asks receivers to reject messages that fail DMARC.

Order SPF→DKIM→DMARC?

Configure SPF and DKIM first, then enable DMARC reporting and tighten the policy step by step.

What do -all, ~all and ?all mean in SPF?

The all qualifier defines how unlisted senders are treated: -all is hard fail (reject), ~all soft fail (mark), ?all neutral. Example: v=spf1 mx ~all allows the MX servers and marks the rest.

Which DMARC tags do I need?

Key tags are v and p (policy) plus pct, rua/ruf (reports) and adkim/aspf (alignment), e.g. v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc@example.com; adkim=s; aspf=s.

Which DKIM key length should I use?

Use at least 2048-bit RSA or alternatively ed25519; 1024-bit keys are considered outdated and should be replaced.