Skip to content
spfdkimdmarcemail-authenticationtoolsemail-deliverability

SPF, DKIM, DMARC Checker: Verify All Three Records at Once

Seeing three different pass/fail screens for SPF, DKIM, and DMARC does not tell you whether your domain is actually protected. Here is what a real spf dkim dmarc checker verifies in one search, and what 591,862 real emails show about pass rates.

Udhayakumar M·
SPF, DKIM, DMARC Checker: Verify All Three Records at Once

Three browser tabs. One SPF checker, one DKIM checker, one DMARC checker. Each one gives you a clean pass or fail, and none of them tells you what the other two found.

That’s the actual problem with checking email authentication one record at a time: you end up with three isolated answers instead of one useful one. SPF can pass, DKIM can pass, and your domain can still be wide open, because the piece that ties them together, DMARC alignment, only shows up when you look at all three at once.

A combined SPF, DKIM, and DMARC checker fixes that by reading all three records in a single search and telling you how they interact. Here’s what it actually verifies, and what real numbers from 591,862 ecommerce emails (11 June to 11 September 2026, from InboxEagle’s inbox placement monitoring) show about how often each record passes on its own.

What a combined checker is actually verifying

Each of the three records answers a different question, which is exactly why checking them separately hides the one that matters most.

Record Question it answers Where it lives
SPF Which servers are allowed to send as this domain? TXT record on the sending domain
DKIM Was this message signed with a valid private key, and is the content unaltered? TXT record at a selector like selector._domainkey.yourdomain.com
DMARC Do SPF or DKIM align with the visible From domain, and what should happen if not? TXT record at _dmarc.yourdomain.com

A single-record checker can only answer its own question. A combined checker cross-references them: it confirms SPF exists and is under the 10-lookup limit, confirms a DKIM selector is published and signing, and then checks whether either one actually aligns with the domain your recipient sees. That alignment check is the part a lone SPF or DKIM lookup structurally cannot do. If you want the full mechanics of how the three records fit together, SPF, DKIM and DMARC explained covers it in depth.

How often each record actually passes

Before you run your own check, here’s a real baseline to compare against.

591,862 Ecommerce Emails, 11 June to 11 September 2026

99.76%of messages passed SPF
99.91%of messages passed DKIM
97.76%of messages passed DMARC

Read literally: SPF and DKIM pass at nearly the same, very high rate, because both are set up automatically by most ESPs during onboarding. DMARC’s 97.76% is the lowest of the three, and that gap is the important part, not the headline number. DMARC doesn’t just check whether a record exists; it checks whether SPF or DKIM aligns with the domain the recipient sees. A message can pass SPF and DKIM cleanly and still fail DMARC if it was signed by a domain the recipient never sees in the From line. And a high message-level pass rate says nothing about domains with no DMARC record at all, which our companion study on missing DMARC records found on 23.4% of the 14,101 ecommerce domains we checked over the same window. High pass rate on the mail you’re already sending is the floor, not proof the record is fully deployed.

Why one passing check isn’t the same as “fully protected”

This is where checking the three records together, instead of in isolation, actually changes what you’d conclude.

Inbox Placement by Authentication State, 11 June to 11 September 2026

Inbox
Promotions
Spam
Fully authenticated577,310 messages
Not fully authenticated14,552 messages

Messages that failed even one of the three checks landed in spam 45.2% of the time, more than double the 20.9% rate for messages that passed all three. A domain where SPF passes and DKIM passes but DMARC alignment quietly fails looks fine on two out of three individual checkers, right up until you look at where the mail actually lands. That’s the practical case for a combined check: it catches the failure mode that two green checkmarks and one red one would otherwise hide until a customer tells you your emails are going to spam. The full breakdown of what authentication failure costs is in our DMARC failure spam folder study.

How to check SPF, DKIM, and DMARC together

Try it on your own domain right now. This runs a live DNS lookup and shows all three results at once, the same three questions a combined checker should answer: does an SPF record exist and how strict is it, is a DKIM selector published and signing, and does a DMARC record exist with an enforcement policy.

Check Your Own Domain

Know your DKIM selector? Enter it for an exact check.

Free, no signup. SPF, DKIM, and DMARC results come from a live DNS lookup; the InboxEagle Monitoring status below checks InboxEagle's own records for this domain.

A weak result on any one of the three is worth tracing back to a cause:

  • SPF exists but resolves with a soft-fail (~all) or permissive (+all) policy instead of a hard fail
  • DKIM shows nothing under common selectors, which usually means a custom selector, not necessarily a missing key
  • DMARC exists but is still at p=none, or is missing outright

For the deeper diagnostics this quick check doesn’t cover, such as SPF’s 10-DNS-lookup limit, the exact DKIM selector your ESP is currently signing with, or DMARC’s alignment and reporting tags, the standalone SPF record checker, DKIM record checker, and DMARC record checker each go further on their own record. For a full audit that also covers BIMI, MTA-STS, and TLS-RPT, run InboxEagle’s free domain scanner.

What to do with the result

  1. If SPF fails, check for too many DNS lookups first. It’s the single most common cause, especially once a domain includes more than two or three sending services.
  2. If DKIM fails, confirm the selector your ESP is currently signing with matches the one published in your DNS. ESPs rotate selectors during key rotation, and the old record left behind will still “exist” without being the one in use.
  3. If DMARC is missing or fails, publish v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com first. It changes nothing about delivery and starts collecting reports on exactly which sources are failing.
  4. If SPF and DKIM both pass individually but the combined check still flags alignment, that’s the failure a single-record checker can’t show you. Trace which sending source is signing with an unaligned domain and fix it there, not in the DMARC record.
  5. Re-run the combined check after any DNS change. A fix to one record can change how the other two evaluate, and the only way to confirm nothing broke is to check all three again, together.

The bottom line

SPF passed on 99.76% of the 591,862 messages we looked at, DKIM on 99.91%, and DMARC on 97.76%. Those three numbers look close together until you remember what DMARC is actually measuring: not just “does the record exist” but “does everything else line up.” That gap is exactly what a combined checker catches and three separate tabs don’t. Check all three together, fix what the alignment failure points to, and re-check after every DNS change.


Want the single-search version of this check on your own domain? Run InboxEagle’s free domain scanner, no account required.


Methodology

Data source: This post reuses previously published data rather than collecting new data. The pass-rate and placement figures come from InboxEagle’s inbox placement monitoring infrastructure, first published in our DMARC record study.

Period: 11 June 2026 to 11 September 2026.

Message dataset: 591,862 ecommerce marketing emails received across inbox, promotions, and spam placements. Every message carried authentication data. SPF passed on 99.76% of messages, DKIM on 99.91%, and DMARC on 97.76%. “Fully authenticated” means a message passed SPF, DKIM, and DMARC (577,310 messages); “not fully authenticated” means at least one check failed (14,552 messages).

Limitations: The dataset reflects ecommerce senders monitored by InboxEagle and skews toward brands using major ESPs such as Klaviyo, Omnisend, and Mailchimp. Pass rates are message-level averages and do not represent every domain equally; a small number of high-volume domains contribute a large share of messages. See the source study’s methodology for the domain-level DMARC record dataset (14,101 domains) and its separate limitations.

Explore with AI

Open this content in your AI assistant for deeper analysis, or copy it as Markdown to paste anywhere.

ChatGPTClaudePerplexity

Frequently Asked Questions

What is an SPF DKIM DMARC checker?
An SPF DKIM DMARC checker is a tool that looks up all three authentication records for a domain in a single search, instead of requiring three separate lookups. It confirms whether an SPF record exists and is under the 10-DNS-lookup limit, whether a DKIM selector is published with a valid key, and whether a DMARC record exists with a readable policy (none, quarantine, or reject). InboxEagle's free domain scanner runs all three checks (plus BIMI, MTA-STS, and TLS-RPT) in one scan and returns a single score.
How do I check SPF and DKIM at the same time?
Enter your domain into a combined tool such as InboxEagle's free domain scanner, which queries the SPF TXT record and the DKIM selector record in the same lookup and reports both results side by side. Checking them separately works too, but a combined check is faster and catches the more common failure: SPF and DKIM each passing individually while still failing DMARC alignment, which a single-record checker won't show you.
How do I check my DMARC record?
Run your root domain through a free DMARC record checker. It confirms the record exists at _dmarc.yourdomain.com, reads the policy (p=none, p=quarantine, or p=reject), and flags syntax errors such as a missing rua= reporting address or two DMARC records published on the same domain. In InboxEagle's dataset of 591,862 ecommerce emails, DMARC passed on 97.76% of messages at the message level, but a per-message pass rate is not the same as having an enforcing policy published, so check the record itself too.
What is a good SPF, DKIM, and DMARC pass rate?
In InboxEagle's study of 591,862 ecommerce marketing emails sent between 11 June and 11 September 2026, SPF passed on 99.76% of messages, DKIM on 99.91%, and DMARC on 97.76%. Those numbers are a reasonable baseline for a healthy sending domain. If your checker returns pass rates meaningfully below that, especially on DMARC, it usually points to an unaligned sending source rather than a broken record.
Do I need to check SPF, DKIM, and DMARC in a specific order?
Check SPF and DKIM first, since DMARC depends on at least one of them passing and aligning with your visible From domain. If SPF and DKIM both check out but DMARC still fails or shows no record, the DMARC record itself is the gap to fix. Re-run all three checks together after any DNS change, since a fix to one record can affect how the other two evaluate.
Udhayakumar M
Udhayakumar M·Content Marketer

With 8+ years writing for 80+ SaaS products, Udhay knows how to make complex ideas land. At InboxEagle, he turns email deliverability data into plain-English strategy — helping eCommerce brands understand why emails end up where they do, and what to do about it.

LinkedIn
Share this article:Share on XShare on LinkedIn

Related Articles

One deliverability insight, every Friday.

Trusted by 2,000+ email senders. Free, always.

Free Checklist

The exact checklist used by 2,000+ email senders to diagnose and fix inbox placement issues — free.

  • Authentication setup (SPF, DKIM, DMARC)
  • Sender reputation signals to monitor
  • List hygiene benchmarks
  • Content & engagement red flags

No spam. Unsubscribe any time.