EMAIL SUITE · 11 TOOLS

Email Authentication Suite

Five DNS records decide whether your mail lands in the inbox or gets refused at the door. This suite reads all of them for any domain — SPF, DKIM, DMARC, BIMI and MTA-STS — explains what each one is doing, and builds the record text when something is missing.

Reads public DNS only
Free, no sign-up
Nothing stored

Try or . On the DKIM tab, add the selector your provider gave you.

The suite

All 11 email tools

The console above runs the six checks people reach for most. Each tool also has its own page with the full explanation, worked examples and its own FAQ.

SPF Record Checker

Audit RFC 7208 SPF records, count DNS lookups against the 10-lookup quota and parse every mechanism and qualifier.

Authentication

SPF Record Generator

Build a valid SPF TXT record from your providers and IP ranges, then copy it straight into DNS.

DNS Generators

DKIM Key Checker

Look up DKIM public keys by selector, decode the tags and flag keys weaker than 2048-bit RSA.

Authentication

DKIM Record Generator

Generate a 2048-bit RSA key pair in your browser and get the matching DNS TXT record — the private key never leaves the page.

DNS Generators

DMARC Policy Checker

Verify your DMARC policy and alignment modes, and see exactly what receivers do with mail that fails.

Authentication

DMARC Record Generator

Walk from p=none to p=reject safely: build the DMARC record with reporting addresses, percentage rollout and alignment.

DNS Generators

BIMI Logo Checker

Inspect BIMI DNS records, preview the SVG brand logo and check the Verified Mark Certificate behind it.

Authentication

BIMI Record Generator

Generate the BIMI TXT record and validate that your logo meets the SVG Tiny P/S profile mailbox providers require.

DNS Generators

MTA-STS Generator

Produce the MTA-STS DNS record, the .well-known policy file and a TLS-RPT record so mail to your domain stays encrypted in transit.

DNS Generators

Email Header Analyzer

Paste raw RFC 5322 headers to trace every relay hop, measure delays and see which authentication checks passed.

Diagnostics

Email Security Score

One 0-100 score and letter grade for a domain, combining SPF, DKIM, DMARC, BIMI and TLS in a single pass.

Diagnostics
Background

What each record actually does

SPF lists who may send

An SPF record names the servers allowed to send mail for your domain. Its catch is the 10-lookup budget in RFC 7208: every include pulls in another record, and those count too. Go over and the record fails outright as a PermError.

DKIM signs each message

Your sending server signs outgoing mail with a private key; receivers fetch the matching public key from selector._domainkey and verify it. A 1024-bit key still validates but is considered weak — 2048-bit is the current baseline.

DMARC decides what happens on failure

SPF and DKIM only produce a pass or a fail. DMARC is the instruction attached to that result: monitor (p=none), send to spam (p=quarantine) or refuse (p=reject). It also requires the passing domain to align with the From address.

BIMI puts your logo in the inbox

Once DMARC is at quarantine or reject, BIMI lets Gmail and Yahoo display your brand logo beside the message. It needs an SVG in the Tiny P/S profile and, for most providers, a Verified Mark Certificate.

MTA-STS keeps transport encrypted

SMTP will quietly fall back to an unencrypted connection if TLS fails. An MTA-STS policy tells sending servers to refuse that downgrade, and TLS-RPT gives you reports when a delivery attempt could not be secured.

Headers show what really happened

When a specific message goes wrong, the records are only half the story. The Received chain in the raw headers shows each relay hop, the delay between them, the originating IP and the authentication result the receiver recorded.

Further reading

Guides and reference

How IncogSay is built

What runs in your browser, what runs at the edge, and why nothing is written down.

Read it →

Link & URL Auditor

The other half of the same problem: checking where a link in a message actually goes.

Open the auditor →

Glossary

Selector, alignment, PermError, VMC, TLS-RPT — the terms these results use, defined once.

Look it up →

FAQ

Answers about accuracy, what is stored, and what each tool can and cannot see.

Browse the FAQ →

Email Authentication Suite — frequently asked questions

QWhat does the email suite check?

It reads the DNS records that decide whether your mail is trusted: SPF, DKIM, DMARC, BIMI and MTA-STS. It also scores the whole set out of 100 and parses raw message headers to show the relay path and which authentication checks passed.

QWhat is the SPF 10-lookup limit?

RFC 7208 allows an SPF evaluation to trigger at most 10 DNS queries — every include, a, mx, ptr, exists and redirect mechanism counts, including the ones inside records you include. Exceeding 10 produces a PermError, and receivers treat that as no SPF at all. The checker counts your real total recursively.

QWhy do I need a DKIM selector?

DKIM public keys are not published at the domain root. They live at selector._domainkey.yourdomain.com, so a lookup needs the selector name. Common ones are google, k1, s1, default, or a provider-specific value from Mailchimp, SendGrid or Microsoft 365.

QWhat does DMARC p=reject do?

It tells receiving mail servers to refuse any message that claims to come from your domain but fails both SPF and DKIM alignment. It is the strongest of the three policies — p=none only monitors, p=quarantine sends failures to spam. Move through them in that order so you can read the reports first.

QWill any of this change my DNS?

No. The checkers only read published records. The generators build the record text for you to paste into your own DNS provider — nothing is published on your behalf, and no credentials are ever requested.

QIs any of this stored?

No. The domain, selector or header block you submit is resolved in memory at the edge and returned to you. Nothing is written to a database or a log, and there are no accounts.