What the email checker checks
When email was invented, nobody thought about scammers: anyone can send an email using your sender address. That’s why there are now three protection records your domain can use to show which emails are genuine. Without them, your messages can quickly end up in the spam folder.
NetScanner checks your domain and tells you in plain words whether everything is in order:
- Can the domain receive email? (MX records)
- SPF: Is it defined which servers are allowed to send email for your domain?
- DKIM: Are your emails digitally signed?
- DMARC: Do receiving mail servers know what to do with fake emails?
For every problem, you get a short, easy-to-understand tip.
The most common problems
No DMARC record. Since 2024, Gmail and Yahoo, and since 2025 Outlook as well, require a DMARC record from anyone who sends large volumes of email. Without one, newsletters and invoices are more likely to land in spam.
Two SPF records. When people add a new service, such as a newsletter tool, they often create a second SPF record. But only one is allowed: all senders belong in the same record.
Too many services in SPF. An SPF record may need no more than 10 lookup steps. With Microsoft, a CRM and a newsletter tool, you can quickly go over that limit.
DKIM never turned on. With many email providers, you first have to activate DKIM.
How to fix the problems
The records are added wherever your domain is managed (for example at GoDaddy, Cloudflare, Hostpoint or Infomaniak). You’ll find step-by-step instructions with examples in our guide How to set up SPF, DKIM and DMARC. After making the changes, simply check again here.
For pros
Under “Technical details for pros” you see the complete records, the number of SPF DNS lookups including nested includes, the DMARC policy and report addresses, any DKIM selectors found, as well as MTA-STS, TLS-RPT and BIMI. If you enter www.example.ch, we automatically check example.ch. The raw TXT records are shown in the DNS lookup.