UNDERSTAND THE RESULT
How to check MX, SPF and DMARC records
Email routing and authentication use several DNS records. NetLuma discovers MX, SPF and DMARC for a domain and highlights basic configuration details. It is a useful first look before reviewing your email provider’s complete setup.
Start with these steps
- Enter the domain after the @ sign, such as example.com. Do not enter a complete email address or a mailbox password.
- Press Check email DNS. The tool looks for MX records, SPF text records and DMARC at _dmarc followed by the domain.
- Review each category and the raw records below it. Compare the values with the instructions for the service that actually handles your email.
What each email record means
- MX · where incoming mail is routed
- Mail server records identify the receiving servers. A null MX record declares that the domain does not accept mail. No MX record can require further investigation rather than proving every address is unusable.
- SPF · a sender authorization policy
- A record beginning with v=spf1 publishes the domain’s SPF policy. Finding one record does not prove that its mechanisms, includes or permitted senders are correct. Multiple SPF records are flagged for review.
- DMARC · handling failed authentication
- The tool recognizes the published p policy. none is monitoring only; quarantine requests suspicious handling; reject requests rejection for messages that fail DMARC. Receiving providers still apply their own handling.
- Attention · read the context
- A monitoring policy can be intentional during a rollout. Missing mail records can also be intentional when a domain does not send or receive email. The color is a prompt to inspect the setup, not an inbox prediction.
What to try next
Use the records as a starting point for your provider’s setup checks. Before tightening a DMARC policy, confirm legitimate sending services authenticate correctly and review available reports. Make configuration changes through the DNS provider responsible for the domain.
Know the limits
NetLuma does not send a test email, evaluate every SPF mechanism, check DKIM selectors or validate alignment for an actual message. Passing these basic checks cannot guarantee email delivery or prevent all spoofing.