Common questions
What does this tool check?
It looks up public DNS for a domain and reviews nameservers, MX, SPF, DKIM, DMARC, DNSSEC, MTA-STS, and common verification records. It also tries to name the vendors behind those records.
What is SPF?
SPF (Sender Policy Framework) is a DNS record that lists which mail services are allowed to send email for your domain. A correct SPF record helps inbox providers trust mail that is actually from you.
What is DKIM?
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outbound mail so receiving servers can confirm the message was not altered and came from your organization.
What is DMARC?
DMARC builds on SPF and DKIM. It tells receiving servers what to do with unauthenticated mail and can send aggregate reports so you can see who is sending as your domain.
Is DMARC p=none a problem?
p=none is a start — it monitors without blocking fake mail. It is better than having no DMARC record, but it does not stop spoofing. Most organizations should move to p=quarantine after reviewing reports, and add a rua address so reports are delivered.
Do parked or vanity domains need these records?
Yes. Extra domains that do not send mail should still publish records that forbid sending, so nobody can spoof them. Typical locked-down values are SPF v=spf1 -all and DMARC p=reject.
Is anything stored when I run a check?
No. Lookups run in your browser against public DNS. Queries and results are not recorded on Good Heart Tech systems.
How do I fix issues this tool finds?
Use the scorecard Fix guide links after a scan, or read our email sender validation guide covering SPF, DKIM, DMARC, DNSSEC, and MTA-STS.