MX Verdict

Free, read-only email and DNS checks: SPF, DKIM, DMARC, MX, DNS lookup, blacklists and a full email domain health check, each with a link to the full report on mxverdict.com.

Hosted MCP Server

npx add-mcp 'https://mxverdict.com/mcp'

Installs into Claude Code, Codex, Cursor and more

Documentation

What the test checks

It is a mail tester that reads a real message: your own mail system sends it over SMTP to our mail server, the way it reaches any receiver. We check SPF, DKIM and DMARC as they came out for that message, the sending server (reverse DNS, its greeting, TLS), the server and the domains of the message on blocklists, the headers and the unsubscribe link, and we give the whole message to a spam filter.

That makes it a spam score checker and an email spam checker in one: the spam score comes from rspamd, an open-source spam filter that runs on our own server. It plays the part a SpamAssassin score plays in other testers, on rspamd’s own scale. The score out of 10 is our weighting of everything above, and every point we take off is listed with its reason.

A second copy goes to our Google Workspace mailbox, so you also see where Gmail put it: the inbox and its tab, or spam. Google applies its sender requirements to personal Gmail accounts, not to Workspace mailboxes, so a personal Gmail inbox can file the same message differently. Outlook and Yahoo mailboxes are not part of the test. Use it to check email deliverability before a campaign goes to your whole list, with the same message sent from the same account or service.

How the score out of 10 works

Every test starts at 10. We take points off for each problem we find in the message and in the way it was sent, and the report lists every deduction with its reason. The weights are our own judgment, built on what Gmail, Yahoo and Outlook.com require of senders: the score is not a number from Gmail or from any standard. Some problems also set a ceiling, so the score cannot go above it however good the rest is. The ones you are most likely to meet:

What we foundPoints offHighest possible score
Neither SPF nor DKIM passedNone3 out of 10
DMARC failed, and the domain asks receivers to reject such mail (p=reject)2.53 out of 10
DMARC failed, and the domain asks receivers to quarantine such mail (p=quarantine)2.56 out of 10
No From address, or more than one13 out of 10
No Message-ID0.33 out of 10
An attachment type that Gmail blocksNone3 out of 10
No DKIM signature1No ceiling
No DMARC record for the From domain1No ceiling
The sending server is on a blocklist that receivers use to refuse mail3 for each list, 4 at mostNo ceiling
The spam filter's score for the content (the ceiling applies from 15 points)0.5 to 43 out of 10

When several ceilings apply, the lowest one counts. A part we could not check, such as a blocklist that did not answer in time, takes nothing off: the score is then marked incomplete and names what is missing, because a gap is never counted as a pass or as a fail. Where Gmail filed the copy is shown next to the score and does not change it. Every report explains its own findings, and the methodology describes how the whole test works.

Is this a SpamAssassin score?

No. The spam score in the report comes from rspamd, an open-source spam filter that runs on our own server, not from SpamAssassin. The two work alike: each has a large set of rules, every rule that fires adds its own points to a total, and the higher the total, the more the message looks like spam. But the rules, their points and their limits are different. SpamAssassin by default treats a message as spam from 5 points. rspamd by default suggests greylisting a message at 4 points, adding a spam header at 6 and rejecting it at 15. A number on one scale does not convert into the other, so we never call ours a SpamAssassin score.

The report lists every rspamd rule that fired, with its points. Rules that measure what we check ourselves (authentication, blocklists, reverse DNS, the server's greeting, the required header fields) are marked there and left out of the content score that counts toward the 10 points, so nothing is counted twice. How the content score turns into points is our own judgment, not a Gmail rule: Gmail publishes no spam score. Under 2 takes nothing off, 2 to 4 takes off 0.5, 4 to 6 takes off 1.5, 6 to 10 takes off 3, 10 to 15 takes off 4, and 15 or more takes off 4 and caps the score at 3. rspamd's own limits apply to its full total, which includes the rules we leave out, so they are only a comparison.

Why an email with a good score can still go to spam

The score reads one message and the server that sent it, at the moment of the test. Receivers also weigh your record as a sender, which one test message cannot show. Gmail, for example, asks senders to keep the spam rate reported in its Postmaster Tools below 0.1% and never to let it reach 0.3%, and Postmaster Tools shows when recipients mark your messages as spam and whether your mail meets Gmail's sender requirements.

A test also cannot see how much you send. Gmail asks more of bulk senders, those that send close to 5,000 messages or more a day to personal Gmail accounts: for example DMARC, and one-click unsubscribe in marketing and subscribed mail. And the mail you send later can differ from the test: other text and links, or another sending service or server.

The Gmail row of the report is one real result, from our one Google Workspace mailbox at one moment. A Workspace administrator can change how spam is filtered, a personal Gmail inbox can place the same message differently, and Outlook and Yahoo inboxes are not part of the test.

How to fix what the test finds

Every finding in the report says what is wrong and links to its explanation. The fixes for the findings people meet most often:

  • SPF failed or is missing. List every service that sends mail for your domain in one SPF record. The SPF record generator page has the steps and what to add for Google Workspace, Microsoft 365, Zoho, SendGrid, Mailgun and Amazon SES, and where to add the record at Cloudflare, GoDaddy and Namecheap.
  • SPF lets every server pass. A record that ends in +all gives a pass to anyone; end it with ~all or -all instead (how the record ends).
  • No DKIM signature, or it failed. Turn on DKIM signing in every service that sends for you and publish the record it gives you: where to use a DKIM key, with the same providers and DNS hosts.
  • No DMARC record, or DMARC failed. DMARC passes only when SPF or DKIM passes for a domain that matches the From address, so fix those first. Then publish a DMARC record, starting with p=none.
  • No reverse DNS, or it does not point back. The reverse DNS (PTR) name of the sending server's address is set by whoever owns that address, your mail provider, sending service or hosting company, not by your DNS host. The name it gives should point back to the same address. The reverse DNS lookup page has the steps for AWS, Google Cloud, Microsoft Azure and common hosting companies.
  • The server's greeting or encryption. Both are settings of the sending server: a full host name that exists in DNS, ideally its reverse DNS name, and STARTTLS turned on. Gmail requires TLS of every sender. If a service sends for you, ask its support.
  • The server or a domain is on a blocklist. The report names each list. Removal is up to that list's operator, not to us or to the receivers: fix what got the address or domain listed, then follow the operator's removal process. The blacklist checker page has the steps and how removal works on each list we check.
  • A header field is missing or doubled. From, Date and Message-ID are added by the program or service that sends the message. Gmail refuses a message without a From address, with more than one, or without a Message-ID, so if you build messages yourself, in code for example, add them once each.
  • A newsletter without one-click unsubscribe. Turn it on in your sending service (RFC 8058). Gmail requires it of senders of 5,000 or more messages a day in marketing and subscribed mail, and Yahoo of bulk senders; transactional mail is excluded.
  • A high spam score. The report's table lists every rule the spam filter fired and its points. Start with the rules that add the most, change what they point at (a link, a phrase, the HTML), and run the test again.

For the DNS records the whole domain depends on, the domain health check has a step-by-step guide: how to fix email deliverability problems.

Mail tester or domain check: which one you need

This mail tester needs a real message. It shows how SPF, DKIM and DMARC came out for that message, what the sending server looked like, what the spam filter made of the content and where our Gmail mailbox put it. Use it when you change what or how you send: a new template, a new sending service, a new server.

The email deliverability check for your domain needs no message. It reads your domain's DNS records: SPF, DMARC, MX, DKIM at common selector names, domain blocklists, MTA-STS, TLS-RPT and BIMI. Use it when you set up a domain or change its records, or to look at a domain you do not send from. It can only try common DKIM selector names, while the test sees the signature your mail really carries.

Tools

Domain checks

DNS lookups

Generators

Email tests

Questions about the test

Is the test free, and how many tests can I run?

Yes, it is free and needs no sign-up. One IP address (for IPv6, one /64 network) can start 5 tests an hour and 20 a day. All networks inside one IPv6 /56 together can start 20 tests an hour and 80 a day. If you reach a limit, the page tells you how long to wait.

Why do I send the email to two addresses?

The first address is on our own mail server: that copy is the one we check and score. The second is in our Google Workspace mailbox, and that copy shows where Gmail put your message. You send one message to both, so the score and the Gmail folder are about the same message. When we have already given out as many Gmail test addresses as we allow in a minute, an hour or a day, a new test gets only the first address and its page says so: the limit keeps Google from blocking the mailbox.

Does the test check Outlook and Yahoo inboxes?

No. The only mailbox in the test is our Google Workspace mailbox at Gmail. Microsoft mailboxes are not part of the test yet, and there is no Yahoo mailbox. The score does follow what Yahoo and Outlook.com publish for senders where it can: for example, Gmail, Yahoo and Outlook.com all expect bulk senders to publish DMARC, and a missing DMARC record takes points off.

Does 10/10 mean my email will reach the inbox?

No. 10/10 means we found nothing to take points off in this message and in the way it was sent. If the score is marked incomplete, some parts could not be checked at all. Where mail lands also depends on things one message cannot show, such as how recipients treat your mail: see why an email with a good score can still go to spam. The Gmail row shows where one real copy landed, next to the score, not in it.

What happens to the email I send?

Our server keeps the message and its report for 7 days and then deletes them; the copy in our Gmail mailbox is deleted within 14 days. We check the message on our own server, never answer or forward it and never open its links: while we check it, only DNS lookups leave our server, for the domains the message names and for the blocklist checks. The report is at a link with a random part, and anyone you give that link to can see it. The report page reaches you through Cloudflare, like every page of this site. The privacy policy has the details, including how to have a test deleted sooner.

How we work

  • Every check result shows the raw answers it is based on, from DNS and, where a check uses them, from mail and web servers, so you can verify it yourself.
  • When we cannot check something (a DNS server does not answer, a lookup times out), we say so. We never turn a gap into a pass or a fail.
  • No registration, no tracking pixels, no cookies, no ads.