Paste any domain. Plain-English DMARC record audit, parsed alignment + policy + reporting endpoints. 3 seconds, no signup.
Answer a few questions, get a paste-ready DMARC record.
Pick your senders, get a valid v=spf1 record under the 10-cap.
Generate a 2048-bit RSA keypair browser-side. Key never leaves you.
Paste raw email headers. We parse the auth chain in plain English.
Verify the BIMI record + SVG logo + VMC chain.
Read the policy file, check the DNS pointer, name the drift.
Paste a raw DMARC XML report, get plain-English back.
Start here.
The two layers underneath.
Step-by-step DNS edits.
Once you're past p=none.
Paste any domain. We fetch its SPF record, walk every include:, count DNS lookups against the RFC 7208 limit of 10, and explain what's tight, what's broken, and what to do next.