Skip to content
Warmuply

Check SPF, DKIM and DMARC: Free Plain-English Checker

The Warmuply TeamLast checked: October 2026

If you send a mail merge from your own Google Workspace address, three settings on your domain help prove your email really comes from you: SPF, DKIM and DMARC. Use this free checker to check SPF, DKIM and DMARC in one go and see, in plain English, which are set up and which need fixing.

The checker only reads public records, so nothing changes on your domain. You don't need to sign up to see your results.

SPF, DKIM and DMARC checker

Enter the domain you send from. We only read public records.

DKIM selector (advanced)

Google Workspace uses google unless you chose something else.

How do you check SPF, DKIM and DMARC with this tool?

  1. Type the domain you send from, like yourcompany.com. You can also paste your full email address, and the checker uses the part after the @.
  2. Leave the DKIM selector as google if you send from Google Workspace. (More on selectors below.)
  3. Press Check my domain.
  4. Fix anything marked red or amber, wait for the change to take effect, then press Check again.

What do SPF, DKIM and DMARC do?

Each is a TXT record, a line of plain text in your domain's DNS. DNS (Domain Name System) is the set of public records attached to your domain. You edit it at your domain host, usually where you bought the domain.

RecordWhat it doesWhere the checker looks
SPF (Sender Policy Framework)Lists the servers allowed to send email for your domainyourcompany.com
DKIM (DomainKeys Identified Mail)Adds a digital signature, so receivers can tell your email is really from you and wasn't changedgoogle._domainkey.yourcompany.com
DMARC (Domain-based Message Authentication, Reporting and Conformance)Tells receivers what to do with email that fails SPF and DKIM, and where to send reports_dmarc.yourcompany.com

DNS settings for yourcompany.com

The checker reads these
  • SPF: who may send

    Type
    TXT
    Name
    @
    Value
    v=spf1 include:_spf.google.com ~all
  • DKIM: your signature key

    Type
    TXT
    Name
    google._domainkey
    Value
    v=DKIM1; k=rsa; p=…
  • DMARC: what to do if checks fail

    Type
    TXT
    Name
    _dmarc
    Value
    v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com
Three records, three names, one place: your domain’s DNS settings.

For the bigger picture, read our plain-English guide to SPF, DKIM and DMARC.

What do the results mean?

Each record gets one of four results.

ResultWhat it meansWhat to do
Pass (green)The record is there and set up correctly.Nothing. Some results include an optional tip.
Needs attention (amber)The record works, but something could cause trouble, like Google missing from your SPF record or no address for DMARC reports.Read the note and apply the suggested change.
Missing or broken (red)There's no record, there are two where there should be one, or a mistake makes receivers ignore it.Copy the fix shown, or follow the setup guide.
Couldn't check (gray)The lookup didn't finish, usually because of a short-lived DNS problem.Wait a minute and check again.

Fix SPF with our SPF setup guide for Google Workspace.

Fix DKIM with our guide to turning on DKIM in Google Workspace.

Fix DMARC with our DMARC setup guide for Google Workspace.

Google says new SPF and DKIM records can take up to 48 hours to start working.

Why can't the checker find my DKIM record?

Usually DKIM isn't turned on yet, or your key uses a different selector. A selector is a short label in the DKIM record's name. Google Workspace uses google by default, so the checker looks there first.

  • DKIM isn't on yet. In Google Workspace, you generate the key in the Google Admin console, add it at your domain host, then click Start authentication.
  • You picked another selector, perhaps because google was already in use on your domain.
  • To find your selector, email a Gmail account from your Workspace address. Open the email, click More (the three dots), then Show original, and find s= in the line starting DKIM-Signature. The word after s= is your selector.

Original message

Simplified
From: you@yourcompany.com
Subject: Quick test
MIME-Version: 1.0
DKIM-Signature: v=1; a=rsa-sha256;
c=relaxed/relaxed;
d=yourcompany.com;Your domain
s=google;This is your selector
h=from:to:subject:date; bh=…; b=…
The value after s= is your selector. Type it into the checker.

What doesn't a passing check tell you?

A clean result means your domain is set up to prove who you are. It doesn't mean your email will land in the inbox.

  • It checks records, not real email. To confirm a message actually passed, open it in Gmail, click Show original, and look for pass next to SPF, DKIM and DMARC.
  • Your sending history still counts. A new or quiet inbox that suddenly sends hundreds of emails looks risky, even with perfect records. Warmuply warms up your inbox in the background and shows how many emails you can safely send each day.
  • Who you email and what you send matter most. Google asks senders to email only people who want their messages, and says spam reports lower a domain's reputation over time. It asks senders to keep their spam rate in Postmaster Tools, Google's free sender dashboard, below 0.3%, ideally below 0.1%.

Warmup builds trust in your inbox. It can't make people want an email they didn't expect.

To see what makes people click "Report spam", read our guide to spam trigger words.

Before you hit send

  • SPF, DKIM and DMARC show no red results in the checker.
  • A test email to a Gmail account shows pass for SPF, DKIM and DMARC under Show original.
  • Everyone on your list expects to hear from you and can easily opt out.
  • You're sending no more than your inbox can safely handle today.

Warmuply checks these settings for you, warms up your inbox, and shows your safe daily send number.

Start a free 7-day trial

Frequently asked questions

Yes, it’s free, and you can see your full results without signing up or giving an email address. If you’d like a copy of your results and the suggested fixes, you can choose to have them emailed to you after the check.

No. The checker only reads your domain’s public DNS records, the same ones every email provider can see. It doesn’t send email from your address, sign in to anything, or change your settings. Any fix you make happens at your domain host.

DNS changes take time to spread. Google says SPF and DKIM can take up to 48 hours to start working after you add them. If you’ve just saved a change, wait a few hours and press Check again. If it still looks wrong after 48 hours, look for typos in the record.

Google requires anyone sending to Gmail accounts to set up SPF or DKIM, and anyone sending more than 5,000 messages a day to Gmail to set up SPF, DKIM and DMARC. Google recommends all three for every domain, so set up all three before your first mail merge.

Yes. Enter the subdomain exactly as you send from it. Google says each subdomain you send from needs its own SPF record. If a subdomain has no DMARC record, receivers use the one on your main domain instead, and the checker shows when that’s happening.

The checker can read the records for any domain, but its suggested fixes are written for Google Workspace, and it tells you when your mail doesn’t seem to run through Google. Warmuply itself supports Google Workspace on your own domain. Microsoft 365 isn’t supported yet.

Sources (8)

Get your inbox ready before you send.

Warmuply warms up your Google Workspace inbox in the background and shows you how many emails you can safely send each day.

Start free for 7 days

No credit card required.

We're launching soon

Get on the waitlist for an exclusive launch discount.

We'll only email you about the launch.