XiaTools
Email tool

Email Security Checker

Get an email security score for a domain based on SPF, DMARC, DKIM, MTA-STS, TLS-RPT and BIMI.

The XiaTools Email Security Checker evaluates your domain's email authentication and transport security posture by analyzing your SPF, DMARC, DKIM, MTA-STS, TLS-RPT, and BIMI configurations. It generates a comprehensive security score to help you identify vulnerabilities that could lead to email spoofing or delivery failures.

What is it

Email security records are DNS entries published by domain administrators to verify the identity of outgoing mail servers and protect message integrity in transit. The Email Security Checker performs automated lookups for these critical records, verifying their presence, syntax, and policy strength. The tool inspects your Sender Policy Framework (SPF) for include limits and mechanisms, DomainKeys Identified Mail (DKIM) selectors for cryptographic signature validity, and Domain-based Message Authentication, Reporting, and Conformance (DMARC) policies to ensure strict enforcement. Additionally, it checks Mail Transfer Agent Strict Transport Security (MTA-STS) and TLS Reporting (TLS-RPT) to guarantee encrypted email delivery, alongside Brand Indicators for Message Identification (BIMI) for visual logo verification.

Why it matters

Without proper email authentication, threat actors can easily spoof your domain to send phishing emails to your customers, partners, and employees. Major mailbox providers like Google and Yahoo enforce strict authentication requirements, meaning domains lacking valid DMARC, SPF, and DKIM configurations will see their legitimate messages sent directly to the spam folder or rejected outright. Implementing these protocols protects your brand reputation, prevents domain hijacking, and ensures high deliverability rates. Furthermore, advanced standards like MTA-STS and TLS-RPT prevent downgrade attacks and interception during transit, while BIMI builds trust by displaying your official brand logo in supported inboxes.

How to use this tool

  1. Navigate to the Email Security Checker page on XiaTools.
  2. Enter your domain name in the input box.
  3. Press Check to initiate the automated DNS and security analysis.
  4. Review the generated security score and detailed protocol breakdown.

How to read the results

The results page displays an overall security score and a breakdown of each evaluated protocol for your domain, using example.com as a reference. The SPF check verifies the record v=spf1 include:_spf.google.com ~all, ensuring authorized senders are explicitly defined. The DMARC check displays your policy, such as v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com, indicating that unauthenticated emails are blocked and aggregate reports are sent. The DKIM check validates your cryptographic selector, while MTA-STS confirms the presence of the policy TXT record and the HTTPS web server configuration. TLS-RPT shows your reporting endpoint for encryption failures, and BIMI confirms whether your SVG logo and Verified Mark Certificate (VMC) are correctly published.

Common problems and how to fix them

Too many DNS lookups in SPF

SPF limits your domain to a maximum of 10 DNS lookup mechanisms, failing entirely if exceeded. Fix this by flattening your SPF record or using a specialized flattening service to reduce nested include statements.

Missing or none DMARC policy

A DMARC policy set to p=none only provides reporting and offers zero protection against spoofing. Update your DMARC record to transition toward enforcement, moving first to p=quarantine and ultimately to p=reject.

Invalid DKIM selector or syntax

Typo errors in your public key selector or formatting issues will cause receiving servers to reject your cryptographic signatures. Verify your key string and replace your record with the exact string provided by your email service provider.

Incomplete MTA-STS setup

MTA-STS requires both a DNS TXT record and a properly configured HTTPS web server hosting the policy file at https://mta-sts.example.com/.well-known/mta-sts.txt. Ensure your SSL certificate is valid and the web server is reachable.

Best practices

Always start your DMARC deployment with a monitoring policy (p=none) and review your XML reports before upgrading to p=quarantine and p=reject. Regularly audit your SPF record to remove third-party services you no longer use, reducing your attack surface and lookup count. Rotate your DKIM keys at least once a year according to your email provider recommendations. Ensure all your mail servers support explicit TLS encryption and publish a TLS-RPT record to catch delivery issues early.

Frequently asked questions

What is an email security score?

An email security score is a calculated metric that rates how well your domain is protected against spoofing, phishing, and interception. It evaluates the presence and strictness of protocols like SPF, DMARC, DKIM, MTA-STS, TLS-RPT, and BIMI.

Why is my DMARC policy set to none failing enforcement?

A DMARC policy of p=none does not fail enforcement because it only monitors traffic and sends reports without blocking emails. While it is useful for gathering data, mailbox providers expect you to eventually upgrade to quarantine or reject policies.

How do I fix SPF lookup limit errors?

The SPF specification limits DNS lookups to 10 per evaluation. You can fix this by removing unnecessary include mechanisms, consolidating third-party senders, or using SPF flattening tools.

What is the difference between MTA-STS and TLS-RPT?

MTA-STS enforces secure TLS connections between mail servers and prevents downgrade attacks, while TLS-RPT provides a reporting mechanism to notify you when encryption failures or connection errors occur.

Do I need BIMI to secure my email?

No, BIMI is not an authentication protocol itself, but rather a branding standard that requires a strict DMARC policy to display your logo. It improves brand recognition in subscriber inboxes but is optional for security.

How often should I check my domain's email security?

You should check your email security posture whenever you change your email provider, add marketing tools, or modify your DNS records. Routine monthly checks help ensure your configurations remain compliant and secure.

Related tools