SPF, DKIM and DMARC monitoring for your domain.
Relvato checks the DNS records that tell mail providers your messages are really from you — SPF, DKIM and DMARC — and flags the setups that break delivery or let anyone send mail as your domain.
- ✓Exactly one SPF record, within the 10-lookup limit
- ✓SPF ends in ~all or -all, not +all
- ✓A single DMARC record with a policy
- ✓A DKIM key is published for your mail provider
Order confirmations, password resets and shipping updates only help if they reach the inbox. A second SPF record added by a new mail tool, an SPF that has grown past 10 DNS lookups, or a missing DMARC policy quietly sends mail to spam — and leaves your domain open to phishing in your name. For whether the site can send mail at all, see email delivery monitoring.
- Reads the SPF record and counts every DNS lookup it needs, following each include:, against the limit of 10 that receivers enforce.
- Reads the DMARC policy at _dmarc and looks for DKIM keys under the selectors the major mail providers use, plus any you add in the check's settings.
- Two SPF or DMARC records, "+all" or more than 10 lookups are problems — each makes receivers reject or distrust your mail; a missing record or a key it can't find is a warning.
It says no DKIM key was found, but my mail is signed.
DKIM keys live under a selector only your mail provider knows. Relvato checks the common ones; add yours in the check's settings — it's the part before ._domainkey in the DNS record your provider gave you.
Is p=none enough for DMARC?
It's the right place to start — it collects reports without affecting delivery. Relvato shows the policy and doesn't flag p=none; move to quarantine or reject once the reports look clean.
Does it send test emails?
No. It only reads public DNS records, so it works for any domain and needs no plugin.
Put this check on autopilot.
Free forever on one site — every check, 100 runs a month. No card, no sales call.