Free domain and email security tools
Instant checkers, generators and analysers for DMARC, SPF, DKIM, SSL, DNS and domain security. All free, no sign-up required.
- Security Grade
Run 16 security checks and get an A+ to F grade.
- SPF, DKIM & DMARC Checker
Check your DMARC policy, SPF record, and DKIM selectors in one scan.
- SPF Checker
Check any domain's SPF record: mechanisms, DNS lookup count, include tree and fail policy.
- DKIM Checker
Scan common DKIM selectors and verify public keys for any domain.
- SSL Certificate Checker
Inspect certificates, expiry dates, and chain validity.
- DNS Lookup
Query any DNS record type instantly.
- SPF Flattener
Resolve SPF includes to a flat list of IPs.
- Lookalike Domain Scanner
Detect typosquat and impersonation domains.
- DNSSEC Checker
Verify DNSSEC signing on any domain.
- MTA-STS Checker
Check MTA-STS policy and TLS enforcement.
- TLS-RPT Checker
Verify TLS-RPT reporting records.
- CAA Checker
Inspect CAA records and certificate issuance restrictions.
- Domain Expiry Checker
Check domain registration status and expiry dates.
- WHOIS Lookup
Query domain registration and ownership data.
- DMARC Record Generator
Build a valid DMARC record in seconds.
- SPF Record Generator
Create an SPF record with your email providers.
- DKIM Record Generator
Generate a DKIM DNS record for your domain.
- CAA Record Generator
Build CAA records to restrict certificate issuance.
- DMARC Report Viewer
Upload and parse DMARC aggregate XML reports.
- Email Header Analyser
Paste email headers and see authentication results, routing hops, and delays.
How to use these tools
The tools fall into three groups. Checkers read what is currently published in DNS for a domain and tell you whether it is valid: the DMARC, SPF, DKIM, DNSSEC, MTA-STS and TLS-RPT checkers all resolve records live at the moment you run them. Generators build a correct record from answers to a few questions, so you can produce a policy without hand-writing the syntax. Analysers take something you already have, such as a raw email header or an aggregate report, and explain what it says.
For a domain you have not audited before, a sensible order is DMARC checker first to see whether a policy exists at all, then SPF and DKIM to confirm the two authentication mechanisms DMARC depends on, then the SSL and DNSSEC checks for the wider domain posture. If SPF fails on a lookup count, the SPF flattener shows which includes are consuming your ten-lookup budget.
Every tool runs without an account and stores nothing about the domains you check. They are point-in-time checks, which is their limitation: they tell you what is published right now, not who has been sending as your domain over the past month. That gap is what continuous DMARC report monitoring covers, because only aggregate reports from receiving mail servers reveal the senders you did not know about. For how these free tools line up against the free tiers other vendors offer, and where each free tier stops, see free DMARC tools compared.