Three browser tabs. One SPF checker, one DKIM checker, one DMARC checker. Each one gives you a clean pass or fail, and none of them tells you what the other two found.
That’s the actual problem with checking email authentication one record at a time: you end up with three isolated answers instead of one useful one. SPF can pass, DKIM can pass, and your domain can still be wide open, because the piece that ties them together, DMARC alignment, only shows up when you look at all three at once.
A combined SPF, DKIM, and DMARC checker fixes that by reading all three records in a single search and telling you how they interact. Here’s what it actually verifies, and what real numbers from 591,862 ecommerce emails (11 June to 11 September 2026, from InboxEagle’s inbox placement monitoring) show about how often each record passes on its own.
What a combined checker is actually verifying
Each of the three records answers a different question, which is exactly why checking them separately hides the one that matters most.
| Record | Question it answers | Where it lives |
|---|---|---|
| SPF | Which servers are allowed to send as this domain? | TXT record on the sending domain |
| DKIM | Was this message signed with a valid private key, and is the content unaltered? | TXT record at a selector like selector._domainkey.yourdomain.com |
| DMARC | Do SPF or DKIM align with the visible From domain, and what should happen if not? | TXT record at _dmarc.yourdomain.com |
A single-record checker can only answer its own question. A combined checker cross-references them: it confirms SPF exists and is under the 10-lookup limit, confirms a DKIM selector is published and signing, and then checks whether either one actually aligns with the domain your recipient sees. That alignment check is the part a lone SPF or DKIM lookup structurally cannot do. If you want the full mechanics of how the three records fit together, SPF, DKIM and DMARC explained covers it in depth.
How often each record actually passes
Before you run your own check, here’s a real baseline to compare against.
591,862 Ecommerce Emails, 11 June to 11 September 2026
Read literally: SPF and DKIM pass at nearly the same, very high rate, because both are set up automatically by most ESPs during onboarding. DMARC’s 97.76% is the lowest of the three, and that gap is the important part, not the headline number. DMARC doesn’t just check whether a record exists; it checks whether SPF or DKIM aligns with the domain the recipient sees. A message can pass SPF and DKIM cleanly and still fail DMARC if it was signed by a domain the recipient never sees in the From line. And a high message-level pass rate says nothing about domains with no DMARC record at all, which our companion study on missing DMARC records found on 23.4% of the 14,101 ecommerce domains we checked over the same window. High pass rate on the mail you’re already sending is the floor, not proof the record is fully deployed.
Why one passing check isn’t the same as “fully protected”
This is where checking the three records together, instead of in isolation, actually changes what you’d conclude.
Inbox Placement by Authentication State, 11 June to 11 September 2026
Messages that failed even one of the three checks landed in spam 45.2% of the time, more than double the 20.9% rate for messages that passed all three. A domain where SPF passes and DKIM passes but DMARC alignment quietly fails looks fine on two out of three individual checkers, right up until you look at where the mail actually lands. That’s the practical case for a combined check: it catches the failure mode that two green checkmarks and one red one would otherwise hide until a customer tells you your emails are going to spam. The full breakdown of what authentication failure costs is in our DMARC failure spam folder study.
How to check SPF, DKIM, and DMARC together
Try it on your own domain right now. This runs a live DNS lookup and shows all three results at once, the same three questions a combined checker should answer: does an SPF record exist and how strict is it, is a DKIM selector published and signing, and does a DMARC record exist with an enforcement policy.
Check Your Own Domain
Know your DKIM selector? Enter it for an exact check.
Active — this domain is already tracked by InboxEagle. Sign up free to unlock its full report.
Inactive — DMARC is set up, but we are not tracking this domain yet.
No Record — no DMARC record was found, so there is nothing to report yet.
Free, no signup. SPF, DKIM, and DMARC results come from a live DNS lookup; the InboxEagle Monitoring status below checks InboxEagle's own records for this domain.
A weak result on any one of the three is worth tracing back to a cause:
- SPF exists but resolves with a soft-fail (
~all) or permissive (+all) policy instead of a hard fail - DKIM shows nothing under common selectors, which usually means a custom selector, not necessarily a missing key
- DMARC exists but is still at
p=none, or is missing outright
For the deeper diagnostics this quick check doesn’t cover, such as SPF’s 10-DNS-lookup limit, the exact DKIM selector your ESP is currently signing with, or DMARC’s alignment and reporting tags, the standalone SPF record checker, DKIM record checker, and DMARC record checker each go further on their own record. For a full audit that also covers BIMI, MTA-STS, and TLS-RPT, run InboxEagle’s free domain scanner.
What to do with the result
- If SPF fails, check for too many DNS lookups first. It’s the single most common cause, especially once a domain includes more than two or three sending services.
- If DKIM fails, confirm the selector your ESP is currently signing with matches the one published in your DNS. ESPs rotate selectors during key rotation, and the old record left behind will still “exist” without being the one in use.
- If DMARC is missing or fails, publish
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comfirst. It changes nothing about delivery and starts collecting reports on exactly which sources are failing. - If SPF and DKIM both pass individually but the combined check still flags alignment, that’s the failure a single-record checker can’t show you. Trace which sending source is signing with an unaligned domain and fix it there, not in the DMARC record.
- Re-run the combined check after any DNS change. A fix to one record can change how the other two evaluate, and the only way to confirm nothing broke is to check all three again, together.
The bottom line
SPF passed on 99.76% of the 591,862 messages we looked at, DKIM on 99.91%, and DMARC on 97.76%. Those three numbers look close together until you remember what DMARC is actually measuring: not just “does the record exist” but “does everything else line up.” That gap is exactly what a combined checker catches and three separate tabs don’t. Check all three together, fix what the alignment failure points to, and re-check after every DNS change.
Want the single-search version of this check on your own domain? Run InboxEagle’s free domain scanner, no account required.
Methodology
Data source: This post reuses previously published data rather than collecting new data. The pass-rate and placement figures come from InboxEagle’s inbox placement monitoring infrastructure, first published in our DMARC record study.
Period: 11 June 2026 to 11 September 2026.
Message dataset: 591,862 ecommerce marketing emails received across inbox, promotions, and spam placements. Every message carried authentication data. SPF passed on 99.76% of messages, DKIM on 99.91%, and DMARC on 97.76%. “Fully authenticated” means a message passed SPF, DKIM, and DMARC (577,310 messages); “not fully authenticated” means at least one check failed (14,552 messages).
Limitations: The dataset reflects ecommerce senders monitored by InboxEagle and skews toward brands using major ESPs such as Klaviyo, Omnisend, and Mailchimp. Pass rates are message-level averages and do not represent every domain equally; a small number of high-volume domains contribute a large share of messages. See the source study’s methodology for the domain-level DMARC record dataset (14,101 domains) and its separate limitations.
