The XiaTools Email Security Checker evaluates your domain's email authentication and transport security posture by analyzing your SPF, DMARC, DKIM, MTA-STS, TLS-RPT, and BIMI configurations. It generates a comprehensive security score to help you identify vulnerabilities that could lead to email spoofing or delivery failures.
What is it
Email security records are DNS entries published by domain administrators to verify the identity of outgoing mail servers and protect message integrity in transit. The Email Security Checker performs automated lookups for these critical records, verifying their presence, syntax, and policy strength. The tool inspects your Sender Policy Framework (SPF) for include limits and mechanisms, DomainKeys Identified Mail (DKIM) selectors for cryptographic signature validity, and Domain-based Message Authentication, Reporting, and Conformance (DMARC) policies to ensure strict enforcement. Additionally, it checks Mail Transfer Agent Strict Transport Security (MTA-STS) and TLS Reporting (TLS-RPT) to guarantee encrypted email delivery, alongside Brand Indicators for Message Identification (BIMI) for visual logo verification.
Why it matters
Without proper email authentication, threat actors can easily spoof your domain to send phishing emails to your customers, partners, and employees. Major mailbox providers like Google and Yahoo enforce strict authentication requirements, meaning domains lacking valid DMARC, SPF, and DKIM configurations will see their legitimate messages sent directly to the spam folder or rejected outright. Implementing these protocols protects your brand reputation, prevents domain hijacking, and ensures high deliverability rates. Furthermore, advanced standards like MTA-STS and TLS-RPT prevent downgrade attacks and interception during transit, while BIMI builds trust by displaying your official brand logo in supported inboxes.
How to use this tool
- Navigate to the Email Security Checker page on XiaTools.
- Enter your domain name in the input box.
- Press Check to initiate the automated DNS and security analysis.
- Review the generated security score and detailed protocol breakdown.
How to read the results
The results page displays an overall security score and a breakdown of each evaluated protocol for your domain, using example.com as a reference. The SPF check verifies the record v=spf1 include:_spf.google.com ~all, ensuring authorized senders are explicitly defined. The DMARC check displays your policy, such as v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com, indicating that unauthenticated emails are blocked and aggregate reports are sent. The DKIM check validates your cryptographic selector, while MTA-STS confirms the presence of the policy TXT record and the HTTPS web server configuration. TLS-RPT shows your reporting endpoint for encryption failures, and BIMI confirms whether your SVG logo and Verified Mark Certificate (VMC) are correctly published.
Common problems and how to fix them
Too many DNS lookups in SPF
SPF limits your domain to a maximum of 10 DNS lookup mechanisms, failing entirely if exceeded. Fix this by flattening your SPF record or using a specialized flattening service to reduce nested include statements.
Missing or none DMARC policy
A DMARC policy set to p=none only provides reporting and offers zero protection against spoofing. Update your DMARC record to transition toward enforcement, moving first to p=quarantine and ultimately to p=reject.
Invalid DKIM selector or syntax
Typo errors in your public key selector or formatting issues will cause receiving servers to reject your cryptographic signatures. Verify your key string and replace your record with the exact string provided by your email service provider.
Incomplete MTA-STS setup
MTA-STS requires both a DNS TXT record and a properly configured HTTPS web server hosting the policy file at https://mta-sts.example.com/.well-known/mta-sts.txt. Ensure your SSL certificate is valid and the web server is reachable.
Best practices
Always start your DMARC deployment with a monitoring policy (p=none) and review your XML reports before upgrading to p=quarantine and p=reject. Regularly audit your SPF record to remove third-party services you no longer use, reducing your attack surface and lookup count. Rotate your DKIM keys at least once a year according to your email provider recommendations. Ensure all your mail servers support explicit TLS encryption and publish a TLS-RPT record to catch delivery issues early.