Validate

Email Deliverability

Broken email authentication does quiet damage twice over: attackers can spoof your domain, and your legitimate mail lands in spam. DNS Watchdog validates the whole stack at RFC level - and scores real test messages the way receivers do.

Product screenshot coming soon

Email authentication fails quietly. An SPF record drifts past the ten-lookup limit during a vendor onboarding and silently stops validating. A DKIM key gets revoked and nobody notices until open rates fall. A missing DMARC record means spoofed mail sails through unchallenged. None of these produce an error anyone sees - they just erode deliverability and hand attackers your domain name.

DNS Watchdog validates the whole stack the way mailbox providers actually evaluate it. SPF is checked against RFC 7208 - mechanism by mechanism, including the ten-lookup limit, the spoofable +all mechanism (raised as High severity), the deprecated ptr mechanism, and a missing catch-all. DKIM records are validated against RFC 6376, including revoked keys published with an empty p= tag. DMARC is checked tag by tag against RFC 7489, MTA-STS records against RFC 8461, and a mail-enabled zone missing any of them entirely is flagged. MX targets that fail to resolve, which means bounced mail, are raised as High-severity issues.

Records only tell half the story, so DNS Watchdog also tests real mail. Your organisation gets a stable test address; send a message to it from the system you want to evaluate, and it is scored out of 10 across ten weighted checks: SPF, DKIM, and DMARC as actually authenticated in transit - with DKIM signatures verified cryptographically against the published key - reverse DNS on the sending IP, blocklist presence, SpamAssassin content analysis reporting your spam score and the exact rules that fired, plus the hygiene factors receivers care about: a List-Unsubscribe header, a plain-text alternative, reachable links and images, and message size.

Every test lands in an inbox view with a mail-tester-style breakdown: each check's verdict, the evidence behind it, and specific remediation guidance. Tests are grouped by sending system - Google Workspace, Microsoft 365, Amazon SES, and others are recognised automatically - so each platform you send through has its own score history. And when a failing SPF or DMARC record sits in a zone connected through a read-write provider, one click on Fix now publishes the corrected record for you.

How it works

  1. Validate the recordsEvery MX-enabled zone across your providers gets daily RFC-level validation - SPF, DKIM, DMARC, and MTA-STS parsed and checked per RFCs 7208, 6376, 7489, and 8461, with missing records and unresolvable MX targets flagged.
  2. Send a test emailYour organisation gets a stable, dedicated test address. Send a message to it from the mail system you want to evaluate - your CRM, your marketing platform, your transactional sender.
  3. Score the messageTen weighted checks run against the real message: transit authentication results, cryptographic DKIM verification, reverse DNS, blocklists, SpamAssassin analysis, and content hygiene - rolled into a score out of 10.
  4. Read the breakdownEach check reports its verdict with the evidence behind it - the record found, the rules that fired, the unreachable URL - and remediation guidance for anything failing, grouped by the sending system it came from.
  5. Fix and re-testFor a failing SPF or DMARC record in a zone on a read-write provider, Fix now publishes the corrected record in one click - then send another test to watch the score move.

What you get

  • SPF, DKIM, DMARC, and MTA-STS validated per RFCs 7208, 6376, 7489, and 8461
  • Permissive +all and missing records flagged on every mail-enabled zone
  • A stable test address: send a real email, get a score out of 10
  • SpamAssassin analysis reporting your spam score and the exact rules that fired
  • Cryptographic DKIM verification, reverse DNS, and blocklist checks on real messages
  • One-click Fix now publishes corrected SPF and DMARC records via your provider

Why it matters

Stop domain spoofing

A permissive or broken SPF/DMARC setup lets anyone send mail as your domain. Closing those gaps protects your customers and your brand from the most common form of impersonation.

Real mail, real verdicts

Records can look perfect while the mail still lands in spam. Scoring an actual message - authentication, reputation, and content together - shows you what receivers actually see.

Catch drift the day it happens

Email DNS records change constantly - new tools, new vendors, new agencies. Daily RFC-level validation means a mistake made this morning is an alert this evening, not a mystery next month.

Every sending system, separately

Your CRM, your marketing platform, and your transactional sender each have their own deliverability. Per-system grouping and score history show you exactly which one needs work.

Common questions

Why does the SPF ten-lookup limit matter?

RFC 7208 caps SPF evaluation at ten DNS lookups. Go over - easy to do with a few include: mechanisms from vendors - and receivers return a permanent error, effectively switching SPF off for your domain. It is one of the most common silent deliverability failures, and DNS Watchdog counts your lookups on every scan.

How does the spam score work?

Your test message is run through SpamAssassin, the analysis most receiving mail systems build on. The finding reports your score against the spam threshold and lists the exact rules that fired, so you know precisely which content or header trait is costing you - and it is weighted into the overall out-of-10 score alongside the other nine checks.

Do you need access to my mail system?

No. The DNS validation is read-only, and the deliverability test works the other way around: you send a message from your system to your DNS Watchdog test address. Nothing connects to your mail infrastructure, and the only messages analysed are the tests you choose to send.

What can Fix now change?

It creates or updates SPF and DMARC TXT records - never deletes anything - in zones connected through a read-write provider, and it shows you the exact record value before you confirm. The proposed fix is built from what the test actually observed, like adding the include for the platform that sent your message.