emailtrace / email diagnostics
every check reports pass, fail, or could not be determined
Paste a domain, a URL, or an address. Nothing is sent to the domain except read-only DNS queries and an SMTP conversation that stops before any recipient is named.
The fields above are optional and each one narrows a check. A sending address gets SPF evaluated against it rather than described, and puts that address on the blocklists alongside the inbound MX. A selector is checked before any guessing starts.
Envelope From and From header are two different identities and the gap between them is where DMARC lives. SPF only ever authenticates the envelope, the one bounces go to. DMARC aligns against the From header, the one your recipient is shown. Give both and the report says whether an SPF pass would actually carry the visible sender, which is the question that decides delivery.
What gets checked
- DNS foundation MX, nameservers, CAA
- SPF expanded, with the 10-lookup budget counted
- DKIM selector sweep and key strength
- DMARC policy, coverage and reporting
- Transport policy MTA-STS and TLS-RPT, policy file fetched
- Live SMTP banner, EHLO, STARTTLS, certificate
- DNSSEC and DANE validation and TLSA
- Blocklists seven lists, each armed before it is believed
- Registration RDAP, expiry and registry locks