CloudSpex

Free domain tool

Email Security Check

Check whether a domain has the basic DNS records needed for trusted email: MX, SPF and DMARC.

What this checks

CloudSpex reads public DNS records in real time and summarizes the result as Good, Needs attention or Problem.

Domain Health Check covers the broader public DNS, SSL, HTTPS, email and subdomain signals available in the Free Scan. For DNS resolution, use the DNS Health Check. For certificate and HTTPS availability, use the SSL Certificate Checker. To see which certificate authorities may issue for the domain, use the CAA Record Checker. To check the available HTTP security headers, use the Security Headers Checker. To focus on a DMARC policy, use the DMARC Checker. To focus on SPF, use the SPF Record Checker. To check one known DKIM selector, use the DKIM Checker. To see what logo a domain declares for BIMI, use the BIMI Record Checker. To confirm whether an MTA-STS policy is actually enforced, use the MTA-STS Checker, which fetches the policy file this page deliberately does not. To see where SMTP TLS delivery reports are sent, use the TLS-RPT Checker.

For a practical overview, read how SPF, DKIM, and DMARC work together.

Frequently asked questions

What does the Email Configuration Health score measure?

It combines the email security signals CloudSpex can read from public DNS: SPF, DKIM, DMARC, MX, MTA-STS and TLS-RPT. Each signal carries a fixed weight and the score is the weighted average of the signals that could actually be measured.

Does CloudSpex test inbox placement?

No. CloudSpex does not send test messages and does not measure whether mail reaches the inbox or the spam folder. The score describes how the domain is configured, not how any particular mailbox provider will treat a message.

Does it check SPF, DKIM and DMARC?

Yes. SPF and DMARC use the same deep analysers as the dedicated SPF and DMARC checkers, including their own 0-100 scores. DKIM is checked against commonly used selectors.

Why can DKIM show "Not fully assessed"?

A domain does not publish a list of its DKIM selectors, so they cannot be discovered from the domain name alone. CloudSpex tries the selectors most providers use. If none of them answers, the domain may still be signing with a selector this check does not know, so DKIM is left unassessed instead of being reported as a failure.

What does "Excluded from the score" mean?

It means the signal could not be measured, so its weight is removed from the calculation instead of being counted as zero. An unmeasured signal never lowers the score. This is different from a signal that was measured and found to be missing, which does count.

Does CloudSpex check MTA-STS?

It reads the _mta-sts DNS record, so it can tell whether a policy is published. It does not fetch the policy file itself, so it cannot confirm whether the policy is in enforce or testing mode, and it never reports a domain as enforced on the strength of the DNS record alone.

Does CloudSpex check TLS-RPT?

Yes. TLS-RPT is a single DNS record, so it is fully measurable here. The check reports whether reporting is configured, how many usable destinations are listed, and whether the record exists but cannot be parsed.

Does this score measure sender reputation?

No. CloudSpex does not currently use blacklist or reputation data, so reputation is not part of this score. Nothing in the result should be read as a statement about how mailbox providers rate this sender.