MonitorDMARC

DNS Record Lookup

Look up DMARC, SPF, DKIM, BIMI, and MX records for any domain. Results are explained in plain English.

The DKIM selector (e.g., 'default', 'google', 'k1')

What do these records mean?

DMARC, SPF, DKIM, BIMI, and MX are all DNS records that control how your email is sent, received, and authenticated. Here's what each one does:

DMARCDomain-based Message Authentication, Reporting, and Conformance

DMARC tells receiving mail servers what to do when an email fails authentication checks. A DMARC policy of p=none means "just monitor, don't take action." A policy of p=quarantine sends failing mail to spam, and p=reject blocks it entirely.

The rua tag specifies where aggregate reports are sent — this is how you find out if someone is spoofing your domain.

SPFSender Policy Framework

SPF lists which mail servers are allowed to send email on behalf of your domain. If you send from Google Workspace, your SPF record includes include:_spf.google.com. When a server receives email claiming to be from your domain, it checks SPF to verify the sender is authorized.

Common problem: SPF has a hard limit of 10 DNS lookups. Exceeding this causes SPF to fail silently.

DKIMDomainKeys Identified Mail

DKIM adds a cryptographic signature to every email you send. The receiving server checks your DKIM DNS record to verify the signature is valid and the email wasn't tampered with in transit. DKIM requires a selector — a label your mail provider uses to identify which key to use.

BIMIBrand Indicators for Message Identification

BIMI is a newer standard that displays your company logo next to emails in supported inboxes (Gmail, Yahoo). It requires a valid DMARC policy of p=quarantine or p=reject before it will work.

MXMail Exchanger

MX records tell the internet which servers receive email for your domain. The priority value (lower = higher priority) determines which server is tried first. Most domains have two MX records for redundancy.