dnstrace.dev
live sources

Mail authentication audit

Test every public layer
protecting your email.

Validate sender authentication, anti-spoofing policy, receiving routes and encrypted mail transport in one report.

Try
Your connection
Detecting… Checking IPv4
Locating network Checking provider

What the result means

A complete email-security check needs more than record detection

A record can exist and still be invalid or ineffective. This audit parses SPF mechanisms, DMARC policy and alignment, DKIM public keys, MTA-STS DNS and HTTPS policy, SMTP TLS reporting, MX routing and BIMI evidence, then separates failures from hardening opportunities.

  • Parsed policy validation
  • Pass, warning and fail findings
  • Exact records and repair guidance

Diagnostic field guide

Use the evidence, not the guess.

Three practical ways to use this lookup, followed by the boundary the result cannot cross.

Reviewed Sep 2026
01

Establish a baseline

Check inbound routing, sender authorization, message signing, anti-spoofing policy and transport controls together.

02

Prepare a provider move

Find authentication records that still authorize or reference the previous mail platform.

03

Prioritize hardening

Separate broken policies from optional improvements instead of treating every missing record as an equal emergency.

How to read the result

  1. Confirm MX and SPF first so the report starts with the domain's visible sending and receiving routes.
  2. Read DKIM and DMARC together because DMARC requires identifier alignment, not record presence alone.
  3. Review MTA-STS and TLS-RPT as inbound transport controls separate from message authentication.

Common questions

Before you act on the result

Do I need SPF, DKIM and DMARC together?

DMARC can pass through aligned SPF or aligned DKIM, but mature deployments usually use both authentication methods and a DMARC policy so forwarding and provider differences do not depend on a single path.

What does the security grade mean?

The grade summarizes the public controls and findings observed during this lookup. It is a configuration aid, not a guarantee of deliverability or a certification of the mail system.

Choose the question

One system, fourteen focused tools.

Each tool has its own indexable page and opens the report at the evidence that answers its question.

Evidence before certainty

The internet has layers.
We keep them separate.

A nameserver identifies the DNS operator. An edge address identifies a public delivery network. An ASN identifies the organization announcing a route. None automatically proves where a hidden origin application runs.

ObservedCorrelatedUnknown stays unknown
Read the detection methodology

Field notes

Read the signal correctly.

All guides

Agent-ready JSON

Give your script or your AI the same public evidence.

GET /api/dns?target=example.com&type=MX
API reference llms.txt

One input, several sources

What a full lookup includes

DNSTrace.dev resolves published DNS answers, follows the primary address to its network owner, and reads registry data for the domain or IP. Your own IP is detected separately and only when this page is open.

DNSRDAPASNGeo IP

Your public network address

What is “My IP”?

Your public IP is the address websites see for your internet connection. It is assigned by your ISP, mobile carrier, workplace, VPN, or proxy and is used to route traffic back to you.

Why it is useful Diagnose your connection

Inspect your ISP, ASN, approximate network location, reverse DNS, and whether traffic is passing through a VPN or hosting network.

What it cannot reveal Not your exact location

IP location usually identifies a city or network region. It does not expose your home address or your device's GPS position.

Privacy Relay-aware, not bypassing

The primary address comes from Cloudflare. An IPv4-only check uses ipify with icanhazip as fallback. Apple Private Relay is verified against Apple's published egress ranges. The original address hidden by a relay cannot be recovered.

Copied