QWhat does the email suite check?
It reads the DNS records that decide whether your mail is trusted: SPF, DKIM, DMARC, BIMI and MTA-STS. It also scores the whole set out of 100 and parses raw message headers to show the relay path and which authentication checks passed.
QWhat is the SPF 10-lookup limit?
RFC 7208 allows an SPF evaluation to trigger at most 10 DNS queries — every include, a, mx, ptr, exists and redirect mechanism counts, including the ones inside records you include. Exceeding 10 produces a PermError, and receivers treat that as no SPF at all. The checker counts your real total recursively.
QWhy do I need a DKIM selector?
DKIM public keys are not published at the domain root. They live at selector._domainkey.yourdomain.com, so a lookup needs the selector name. Common ones are google, k1, s1, default, or a provider-specific value from Mailchimp, SendGrid or Microsoft 365.
QWhat does DMARC p=reject do?
It tells receiving mail servers to refuse any message that claims to come from your domain but fails both SPF and DKIM alignment. It is the strongest of the three policies — p=none only monitors, p=quarantine sends failures to spam. Move through them in that order so you can read the reports first.
QWill any of this change my DNS?
No. The checkers only read published records. The generators build the record text for you to paste into your own DNS provider — nothing is published on your behalf, and no credentials are ever requested.
QIs any of this stored?
No. The domain, selector or header block you submit is resolved in memory at the edge and returned to you. Nothing is written to a database or a log, and there are no accounts.