emailtrace / email diagnostics

every check reports pass, fail, or could not be determined

Paste a domain, a URL, or an address. Nothing is sent to the domain except read-only DNS queries and an SMTP conversation that stops before any recipient is named.

The fields above are optional and each one narrows a check. A sending address gets SPF evaluated against it rather than described, and puts that address on the blocklists alongside the inbound MX. A selector is checked before any guessing starts.

Envelope From and From header are two different identities and the gap between them is where DMARC lives. SPF only ever authenticates the envelope, the one bounces go to. DMARC aligns against the From header, the one your recipient is shown. Give both and the report says whether an SPF pass would actually carry the visible sender, which is the question that decides delivery.

Load DMARC aggregate reports

Drop in the files exactly as they arrived: .xml, .xml.gz or .zip, several at once. The format is detected from the file contents, not its name.

drop report files here

Reports are parsed in this browser. Nothing is uploaded, and no DNS query is made. ⚠️ One exception, and only if you ask for it: the sources table offers a button that looks up how old the sending domains are, which sends those domain names to this server so it can query a registry. Nothing else in a report ever leaves this tab.

What gets checked