LOCAL PREVIEW · placeholders marked TODO · prices are proposed, not live · nothing here takes payment

Free email authentication checker

Is your email going to spam? Find out why in 10 seconds.

Free SPF, DKIM and DMARC checker. Enter your domain and get a plain-English pass/warn/fail for each record, plus the exact fix. No sign-up, nothing to install.

Runs in your browser. We only ask public DNS (Cloudflare 1.1.1.1, falling back to Google) for your domain's public records. Nothing is stored. What are the bulk-sender rules?

Sender rules

The sender rules now in force in 2026

Gmail and Yahoo have enforced these since February 2024; Outlook.com since May 2025. Here is what each one asks for, in plain English.

Gmail & Yahoo (since Feb 2024)

  • Everyone who emails Gmail/Yahoo addresses needs SPF or DKIM, valid DNS (forward and reverse), and TLS.
  • Bulk senders (about 5,000+ messages a day to Gmail addresses; Yahoo publishes no number) need SPF and DKIM and a DMARC record (at least p=none), with your visible From domain aligned to SPF or DKIM.
  • DKIM keys should be at least 1024-bit; 2048-bit is recommended.
  • Marketing mail needs one-click unsubscribe (honoured within 2 days) and a spam-complaint rate kept under 0.1% (never 0.3%+).
  • Enforcement has tightened: since November 2025 Gmail has been ramping up enforcement, so non-compliant mail can now get temporary and permanent rejections, not just spam-foldering.

Outlook.com / Hotmail / Live (since May 5, 2025)

  • Domains sending 5,000+ messages a day to Microsoft consumer mailboxes must pass SPF and DKIM and publish DMARC (minimum p=none) that passes through an aligned SPF or DKIM.
  • Non-compliant mail is rejected with 550 5.7.515 (Microsoft's own pages also describe sending it to Junk first), so plan for either outcome.
  • This applies to consumer Outlook.com, not to Exchange Online/Microsoft 365 recipients.

"But I only send a few hundred emails…"

The formal bulk thresholds are high, but in practice small senders without SPF/DKIM/DMARC get filtered more, and a missing DMARC record lets anyone spoof your domain. The "everyone" rules (SPF or DKIM) already apply to you. These three records are cheap insurance and the baseline every mailbox provider expects. Google also says aligning to both SPF and DKIM will likely become a requirement eventually.

Sources: Google's Email sender guidelines and FAQ, Yahoo Sender Hub, and Microsoft's 550 5.7.515 page and "Strengthening Email Ecosystem" announcement (checked Oct 2026). Thresholds and enforcement details change; check the provider pages for current wording. TODO(Sam): re-verify these rules before launch.

Done for you

Email authentication fixed for you, at a fixed price

Your invoices, order confirmations and newsletters are landing in spam, or bouncing. We set up SPF, DKIM and DMARC correctly on your domain, then prove it with real test emails.

Who this is for

  • Small businesses and consultants on Google Workspace, Microsoft 365, Zoho or similar whose mail to clients lands in junk.
  • Creators and newsletter writers sending through Mailchimp, Substack-on-custom-domain, ConvertKit, Beehiiv and the like.
  • Online stores (Shopify, WooCommerce, etc.) whose order and receipt emails don't arrive.
  • Anyone who got the "your domain doesn't meet Gmail/Yahoo/Outlook requirements" notice and doesn't want to learn DNS.

Not a fit: sending huge lists or cold outreach with a damaged sender reputation (authentication alone won't fix that), or spam-complaint problems caused by the content itself.

How it works

Four steps. Proven with a real email.

  1. Tell us your domain and who sends your email

    Mailbox provider, plus tools like newsletter, store, CRM and invoicing. Takes about 5 minutes.
  2. Pick how the DNS changes get made

    Option A, we do it: give us temporary or delegated access to your DNS (see the FAQ for how to do this safely). Option B, guide mode: we send you the exact records and copy-paste steps, you add them yourself, and we check each one. No access given.
  3. We configure SPF, DKIM and DMARC

    One merged SPF record (under the 10-lookup limit), DKIM for your mailbox provider and up to 3 sending services, and DMARC in monitor mode with reports going to you.
  4. We verify with real test emails

    We send test messages from your actual senders to Gmail and Outlook.com test inboxes and check the headers show SPF, DKIM and DMARC pass with the right alignment. You get a short written report plus a plan for moving DMARC to enforcement safely.

Pricing

One fixed price. Refund if the tests fail. PROPOSED · not final

Optional: DMARC enforcement rollout

$190 add-on
  • 30 days of monitoring the DMARC reports
  • Find and authenticate legitimate senders you forgot
  • Staged move from p=none to quarantine to reject when reports are clean

Only worth it if you want protection against people spoofing your domain. Not needed to meet the bulk-sender minimum.

Prefer to do it yourself?

Free

The checker above tells you exactly what to change. Many people fix it themselves in under an hour. Run the checker.

The pricing here is modelled on what competing fixed-price providers charge; it is a test price.

$199 fixed price, one domain, plus the optional +$190 DMARC enforcement add-on. Setups with 3+ sending services are quoted before any work starts. PROPOSED · not final TODO(Sam): confirm $199, and decide whether to offer a cheaper single-sender tier or a surcharge for 3+ sending services.

The guarantee, stated honestly

After we finish, we send test emails from your real senders to Gmail and Outlook.com test inboxes. If those test messages don't show SPF, DKIM and DMARC passing (aligned to your From domain) for the senders in scope, we keep working on it, and if we still can't get them to pass, you get a full refund.

What we do not promise: inbox placement. Whether a given message reaches the inbox also depends on your sending reputation, list quality, content, and blocklists, which authentication cannot fix. We'll tell you if we see those problems.

Out of scope: senders that can't sign with your domain on their plan, DNS hosts that don't let you or us add the needed records, and domains with active blocklisting or abuse problems. We'll say so up front, before you pay where we can, and refund if it only becomes clear after. TODO(Sam): have this wording reviewed and decide the exact refund window/terms before going live.

FAQs

The questions every owner asks

Do I have to give you access to my DNS? Is that safe?

No, you don't have to. Guide mode is a first-class option: we tell you exactly which records to add (host, type, value), you paste them into your DNS provider yourself, and we verify each one from the outside using public DNS and test emails. You never share a password.

If you'd rather we do it, the safest ways are: add us as a limited user/delegate in your DNS provider (Cloudflare, GoDaddy, Namecheap, Google Domains-successors and others support this) and remove us afterwards, or screen-share while you click. We never ask for your registrar login, we don't store credentials, and you can revoke access the moment we say we're done. We never need access to your mailbox contents.

Could this break my existing email?

That's the risk we design around. We start DMARC at p=none (monitor only, nothing gets blocked), we check every sender you use before touching SPF, and we keep a copy of your original records so changes can be rolled back. We never switch to quarantine or reject without evidence from the reports (that is the optional add-on).

What exactly is "tests pass"?

We send test emails from each in-scope sender to Gmail and Outlook.com inboxes and read the Authentication-Results headers. The test passes when SPF, DKIM and DMARC all show pass, aligned to your From domain. We include the headers in the report so you can see for yourself.

Will this guarantee my emails reach the inbox?

No, and be wary of anyone who says it will. Correct authentication removes a major reason for spam filtering and is required by Gmail, Yahoo and Outlook.com for bulk senders. Reputation, content and list quality still matter.

I already have SPF/DKIM/DMARC. Can't I just use a free tool?

Yes, if the checker above shows green, you probably don't need us. Our value is for when it's red or you can't tell what to change: we make the change, handle the awkward cases (multiple senders, SPF lookup limits, third-party tools) and prove it works with a real email.

What do you need from me?

Your domain, the mailbox provider and any tools that send as you, and either DNS access (delegated/temporary) or willingness to paste records in guide mode. Plus an address we can send test emails from, or a test inbox you can forward headers from.

What about additional domains or unusual setups?

The base price covers one domain. Each extra domain is $149. On-premise mail servers or very complex setups are quoted separately before any work starts.

Who is behind this?

Run by an engineer who sets up and verifies mail authentication. TODO(Sam): add a real number or name here later (e.g. a verifiable count of setups, or your first name). Do not add figures that are not true.

Contact

Ready to fix it?

Nothing is submitted from this page. The button below opens your own email app with a pre-filled request to sales@wrenchline.ai, so no form backend is involved.

Email my request