Skip to main content
Free Tools

46 Free Email Security Tools

Check, generate, analyze, and look up DNS records for every email authentication protocol. All tools run in your browser — nothing is sent to our servers.

100% client-side — your data never leaves your browser

Checkers

DMARC

DMARC Record Checker

Validate your DMARC policy, parse all tags per RFC 7489, and get actionable recommendations.

Check
SPF

SPF Record Checker

Parse SPF mechanisms, count DNS lookups against the RFC 7208 limit of 10, and detect misconfigurations.

Check
DKIM

DKIM Record Checker

Look up DKIM public keys by selector, verify key sizes against RFC 8301, and check algorithm compliance.

Check
BIMI

BIMI Record Checker

Verify your BIMI record, check SVG logo compliance, VMC authority, and DMARC enforcement prerequisites.

Check
MTA-STS

MTA-STS Checker

Validate your MTA-STS DNS record, fetch the policy file, and verify MX record alignment per RFC 8461.

Check
TLS-RPT

TLS-RPT Record Checker

Check your TLS-RPT DNS record, validate report destinations, and verify MTA-STS integration per RFC 8460.

Check
DANE

DANE/TLSA Record Checker

Look up TLSA records, verify DNSSEC status, and validate DANE configuration per RFC 6698 and RFC 7672.

Check
Reputation

Blacklist Check

Check if your domain or IP appears on major DNS blacklists (DNSBLs) that could affect email deliverability.

Check
ARC

ARC Readiness Checker

Assess ARC readiness by checking DMARC enforcement, mail provider capabilities, and DKIM keys at common ARC selectors.

Check
ARF

ARF / Forensic Report Checker

Validate DMARC forensic reporting — check ruf= destinations, external authorization, failure options, and provider support.

Check
DMARC

DMARC Failure Diagnoser

Seeing DMARC failures in your reports or bounces? Get the most likely causes ranked by impact — missing record, p=none silent failure, SPF misalignment, DKIM gaps, forwarding breaks — with the exact fix for each.

Diagnose
DKIM

DKIM CNAME Validator

ESPs publish DKIM via CNAME so they can rotate keys server-side. Walk the chain (loop-safe), resolve the terminal TXT, and validate the DKIM key per RFC 8301 — flagging dangling aliases and weak keys.

Validate
SPF

SPF Record Syntax Inspector

Paste an SPF record or fetch from a domain — get a token-by-token breakdown with every mechanism, qualifier, and modifier mapped to its RFC 7208 section, plus the common pitfalls flagged inline.

Inspect
SPF

SPF Macro Debugger

Expand %{i}, %{s}, %{d}, %{l}, %{o}, %{h}, %{v}, %{p} with your own evaluation context. See the per-macro transform (digits, reverse, delimiters) before publishing a record — and understand the per-IP and per-sender authorisation patterns most receivers never document.

Debug macros

Generators

Analyzers

Lookups & Diagnostics

Compliance & Audit

EU · NIS2

NIS2 Readiness Scorecard

NIS2 is in force EU-wide; enforcement is rolling out through 2026 (Germany live 6 Dec 2025). Check your domain against the NIS2 Article 21 §2(d), §2(g), and §2(h) email-authentication controls and get the gaps named in auditor language.

Run scorecard
DE · BSI

BSI NIS2 E-Mail-Sicherheitscheck

NIS2UmsuCG seit 6. Dez. 2025 in Kraft (BSI-Registrierung läuft). Prüfung gegen die BSI-Grundschutz-Bausteine NET.4.2, NET.4.3 und CON.5 — deutsche Auditor-Sprache, §-Verweise auf NIS2UmsuCG.

Prüfung starten
EU · DORA

DORA ICT Email Control Mapper

DORA in full effect since 17 Jan 2025. Map DMARC, SPF, MTA-STS, TLS-RPT, and DNSSEC posture to Articles 9, 10, and 11 — built for EU financial entities preparing for supervisor reviews.

Run check
DE · DORA

DORA E-Mail-Sicherheitscheck

DORA gilt seit 17. Januar 2025 für EU-Finanzunternehmen. Prüfung gegen Artikel 9, 10 und 11 — deutsche Auditor-Sprache mit BaFin- und MaRisk-Bezug.

Prüfung starten
PCI DSS 4.0.1

PCI § 5.4.1 Anti-Phishing Checker

Req 5.4.1 mandatory since 31 March 2025. QSA-ready anti-phishing mechanism evidence — DMARC at enforcement, SPF, MTA-STS, TLS-RPT — mapped to PCI SSC's April 2024 email protocol supplement.

Run check
US · HIPAA

HIPAA Email Authentication Readiness

HHS published the first Security Rule update since 2013 in Dec 2024. Check your domain against §164.312 Technical Safeguards before the 2026 OCR audit cohort lands. 74% of breached healthcare domains lacked effective DMARC.

Run check
Microsoft

Microsoft 550 5.7.15 Bulk Sender Diagnostic

Outlook started rejecting bulk-sender mail that fails DMARC verification on 5 May 2025. Diagnose your domain against Microsoft's high-volume sender requirements and get the exact DNS records to publish.

Diagnose
Gmail & Yahoo

Gmail & Yahoo Bulk-Sender Readiness

Google and Yahoo enforce SPF + DKIM + DMARC alignment on bulk senders since 1 February 2024. Gmail's November 2025 escalation moved repeat offenders from tempfail to permanent rejection.

Run check
UK · NCSC

NCSC Mail Check Migration

NCSC Mail Check retired on 31 March 2026. Run the equivalent posture check on your domain — DMARC, SPF, MTA-STS, TLS-RPT — and download an MCSS-aligned migration report.

Run check
Migration

p=none Escape Plan — 4-Week Wizard

Stuck at p=none? Enter your domain and get a personalised four-week migration plan that walks from monitoring to p=quarantine to p=reject. Includes the exact DNS record at every step.

Build my plan
EU · NIS2

NIS2 Supplier Questionnaire

Paste or upload a supplier list, get a NIS2 §21(2)(d) supply-chain readiness report in seconds. Each supplier scored against DMARC, SPF, MTA-STS. Downloadable as CSV evidence.

Scan suppliers