Learn how to check the au­then­tic­i­ty and security of your emails with a quick DMARC check. We’ll also provide you with a list of DMARC checkers you can use.

What is a DMARC check and why is it important?

Companies need to be sure that important emails reach their customers and business partners. To check the au­then­tic­i­ty and security of emails and email domains, DMARC checkers are useful. These tools validate the au­then­tic­i­ty of an email by checking entries for DMARC (Domain-based Message Au­then­ti­ca­tion Reporting and Con­for­mance), SPF (Sender Policy Framework) and DKIM (Domain Keys Iden­ti­fied Mail). DMARC is used to integrate SPF and DKIM in a unified framework and to monitor your email traffic according to fixed policies. DMARC’s three main functions are:

  • Reject: The recipient server rejects your email based on a failed DMARC test.
  • Quar­an­tine: Emails that fail the DMARC test are moved to the spam folder of the recipient address.
  • No Action: No action is taken on the part of the sender even if the DMARC test is not passed.

The rules that are applied in the event of a failed security check are defined in a TXT record in the DMARC entry (DMARC record). The TXT record is published to the Domain Name System for DMARC review. In the DMARC record, you can define whether recipient servers should reject unau­then­ti­cat­ed emails from your domain. You can also define if and how you are informed about domain abuse or DMARC errors. With an in­te­grat­ed DMARC check, you receive daily reports on your email traffic, including the following in­for­ma­tion:

  • What per­cent­age of emails pass DMARC checks?
  • How many emails are rejected by recipient servers?
  • Which servers or ap­pli­ca­tions are used to send rejected emails?
  • Which servers or ap­pli­ca­tions are sending all the emails, or more specif­i­cal­ly, all the emails assigned to your domain?

What happens if DMARC is set up in­cor­rect­ly?

Email cor­re­spon­dence with customers and business partners is a primary target for cy­ber­crim­i­nals. It’s important for companies to be aware of a common spoofing attack, in which fraud­u­lent emails are made to appear authentic. This often involves the use of phishing emails. In phishing, cy­ber­crim­i­nals pretend to send emails from your email domain or business email in order to obtain the personal data of email re­cip­i­ents. Correct DMARC entries ensure that phishing emails or spam campaigns under your domain do not end up in re­cip­i­ents’ inboxes and can be stopped as quickly as possible.

For reliable email security, it is important to configure DMARC records correctly. In addition to using your own domains, you should also use strong passwords and SSL. If you have DMARC failed in a DMARC report, it may be due to several reasons:

  1. Your email domain has been block­list­ed due to abuse such as spam campaigns.
  2. Your cre­den­tials were stolen, and malicious emails were sent through your domain.
  3. Your DMARC record has been set up in­cor­rect­ly.

In the latter case, it may be an incorrect DMARC matching mode, missing DKIM signature or missing DNS TXT records. Since there is no acute threat in the case of a DMARC policy that has been in­cor­rect­ly set up, DMARC error messages can be quickly corrected with the right DMARC checkers.

What DMARC checkers are available?

There are several analysis, mon­i­tor­ing and reporting tools available to check your DMARC con­fig­u­ra­tions. Which DMARC checker is best depends on how detailed and com­pre­hen­sive you want the analysis to be. There are fully in­te­grat­ed, complex DMARC tools that fully automate testing and analysis and serve multiple domains si­mul­ta­ne­ous­ly. However, these require knowledge of handling, con­fig­ur­ing and analyzing DMARC. In addition, there are simple DMARC checkers that apply best practices and provide a quick overview of the status of one’s own email security.

For example, you can use one of the following three tools:

Dmarcian

Image: Web browser: Dmarcian website
Web browser: Dmarcian website

Dmarcian was founded in 2012 and is one of the most well-known services that DMARC offers using the SaaS model. One reason that it is widely used and respected is that it was founded by Tim Draegen, a co-developer of the DMARC standard. Depending on your needs, Dmarcian offers com­pre­hen­sive analysis tools for DMARC, ranging from a quick and easy review of a few emails to com­pre­hen­sive email datasets and complex analysis spec­i­fi­ca­tions. This is com­ple­ment­ed by reliable support and a variety of pricing models. However, because Dmarcian is among the more complex tools for DMARC checks, smaller or­ga­ni­za­tions and teams may feel over­whelmed by its com­plex­i­ty.

In addition to the pro­fes­sion­al DMARC man­age­ment platform, Dmarcian offers free tools for DMARC checks. Even without a Dmarcian account or sub­scrip­tion, these tools are always available to you. These include:

  • Domain Checker: Checks domains (both your own domain as well as others) regarding SPF/DKIM/DMARC pa­ra­me­ters
  • DMARC Inspector: Checks domains and cor­re­spond­ing DMARC records
  • DMARC Record Wizard: Supports you with the con­fig­u­ra­tion of your DMARC record
  • SPF Surveyor: Provides a graphical view and diagnosis of SPF records
  • DKIM Inspector: A di­ag­nos­tic tool for DKIM entries
  • DKIM Validator: A di­ag­nos­tic tool used to validate your DKIM entries
  • XML-to-Human Converter: Trans­lates DMARC records into an easier-to-read format that fa­cil­i­tates report analysis

DMARC Digests

Image: Web browser: DMARC Digests website
Web browser: DMARC Digests website

Founded in 2020, DMARC Digests is one of the youngest DMARC services on the market. What sets DMARC Digests apart from other services is that it is a DMARC tool that is easy and intuitive to use while providing good DMARC func­tion­al­i­ty. The service is par­tic­u­lar­ly suitable for smaller companies that want to quickly check a man­age­able number of emails for DMARC integrity and only require more in-depth analysis if it’s needed. However, in favor of usability, features such as forensic DMARC analyses, alerts and APIs are missing.

DMARC Digests offers the following features:

  • Mon­i­tor­ing of email activity and delivery history under your mail domain
  • Trou­bleshoot­ing and analysis of DMARC errors as well as analysis of unau­then­ti­cat­ed emails and SPF/DKIM issues
  • Automated problem res­o­lu­tion and suggested solutions
  • 60-day overview of all email senders and servers for your domain
  • Weekly and monthly problem reports and advice on op­ti­miz­ing DMARC con­fig­u­ra­tions
  • Team func­tion­al­i­ties for team-based DMARC analysis

MxToolbox

Image: Web browser: MxToolbox website
Web browser: MxToolbox website

MxToolbox is also a provider of email and DNS au­then­ti­ca­tion, blocklist lookup, and secure emailing tools. This also includes free or paid tools for analyzing DMARC/DKIM/SPF records. For free DMARC checks, MxToolbox offers the following services:

  • DMARC Record Test: This di­ag­nos­tic tool for DMARC record checks displays the DMARC record of domains (both your own domain as well as third-party domains) and lists ad­di­tion­al an­a­lyt­i­cal data on the DMARC status.
  • DMARC Generator: This tool supports you in creating and con­fig­ur­ing DMARC records and offers a beginner-friendly, step-by-step approach for this purpose.
  • DMARC Report Analyzer: Converts DMARC XML reports into an easy-to-read format, sim­pli­fy­ing the eval­u­a­tion and cor­rec­tion of TXT records of your DMARC policy.
  • SPF Record Check: Displays a domain’s SPF records and lists as­so­ci­at­ed di­ag­nos­tic data.
  • SPF Record Generator: Assists in the creation and editing of SPF records.
  • DKIM Test & Validator: Analyzes DKIM records and displays as­so­ci­at­ed analysis data.

What are the benefits of email and DMARC testing tools?

Email traffic between companies and their customers or business partners is one of the preferred attack surfaces for cy­ber­crim­i­nals. A trans­par­ent analysis and con­tin­u­ous mon­i­tor­ing of email traffic via your own domain therefore increases your security and the security of your partners and target audience. In addition, you ensure that important marketing or business emails do not end up in spam folders but in the inboxes of your re­cip­i­ents.

The ad­van­tages of DMARC and email checks are as follows:

  • Possible errors with sending emails are quickly detected and corrected.
  • Email traffic between companies, partners and customers is protected (as well as pro­tec­tion against spoofing and spam).
  • Analysis reports enable fast cor­rec­tions of DMARC/SPF/DKIM entries.
  • Marketing campaigns can be checked in advance for email domain integrity and re­li­a­bil­i­ty.
  • Important emails don’t end up in re­cip­i­ents’ spam folders without you knowing.
  • Reliable, secure and au­then­ti­cat­ed emails strength­en brand image and the trust of partners and customers.
Tip

Make a serious and pro­fes­sion­al im­pres­sion by creating your own business email address. In addition to being ad-free, IONOS’ email solution comes with a custom domain and pro­tec­tion against spam and viruses.

How to do a manual DMARC test

Don’t want to use DMARC tools? DMARC can also be tested manually, however, the scope of manual testing is limited. DMARC checks that are performed using a SaaS solution from one of the pro­fes­sion­al DMARC providers mentioned in the previous section are faster and more secure. They can also be carried out au­to­mat­i­cal­ly.

For a manual DMARC test, an analysis of the email header is a good idea. We’ll show you how to do this in Gmail, Apple Mail, Outlook, Mozilla and Opera.

Gmail

The following example is a DMARC test for Gmail accounts. With Google, you can use the free Google tool Toolbox Mes­sage­head­er to check DMARC for au­then­tic­i­ty and cor­rect­ness. In other email services like Apple Mail, Mozilla, Hotmail or Outlook, the procedure may differ.

  1. Send an email to your Gmail account or access an email that you want to test.
  2. Open the email and click the three-dot icon in the top right corner.
  3. Select the View original option.
  4. In the original view of the email, you can see all the in­for­ma­tion such as email sender, email servers passed through, and au­then­ti­ca­tion results for SPF and DKIM, as well as DMARC policies. In addition to the Created on entry, you can also check whether there was any no­tice­able delay in sending the message.
  5. Copy the text of the original mail with all the in­for­ma­tion.
  6. Now open the Google tool Mes­sage­head­er and paste the copied text under Paste email header here.
  7. Select Analyze the header above and wait for the manual ver­i­fi­ca­tion to complete.

Apple Mail

  1. Open Apple Mail and the email you want to check.
  2. Go to View and then Message > All Headers.
  3. You will now see the email header in a separate window with all the in­for­ma­tion about the email and the sending history.

Outlook

  1. Open Outlook and the email you want to test.
  2. Go to File and to Prop­er­ties. In the Internet headers field, you’ll find detailed in­for­ma­tion about the email.

Mozilla

  1. In Mozilla, open the email you want to check.
  2. Then go to View and Message Source to get a breakdown of the email in­for­ma­tion.
Go to Main Menu