What this spam checker actually tests
Most tools called a "spam test" ask you to send a message to a throwaway address and then grade the result. That measures one delivery, once, from one server. This one measures something more durable: how much of your domain's trust is established before a message is ever sent.
Every signal below is read live from public DNS the moment you press Check — nothing is cached, nothing is inferred from a previous visitor's lookup, and no email leaves your mail server:
- DMARC — whether a record exists at
_dmarc.yourdomain.com, whether it parses, what policy it declares, and whether it names an address to send reports to. - SPF — whether a valid record exists, how many DNS lookups it costs to evaluate, and how it ends:
-all,~allor nothing. - DKIM — whether any public signing key can be found, probed across 83 measured selector names.
- MX — whether the domain is set up to receive mail at all.
- Blocklists — whether the IPs behind your MX records are listed.
These are the signals a receiving filter can evaluate on its own, without ever having seen your domain before. Content heuristics — spammy phrasing, image-to-text ratio, link reputation — matter too, but they matter after authentication. A domain that fails authentication starts every message from a deficit no subject line can recover.
How the score is calculated
The scale is published rather than proprietary, because a number you can't reconstruct is a number you can't act on. One hundred points are distributed across the signals filters actually weigh:
- DMARC record — up to 25. A valid record earns 25; one that parses but carries a warning earns 10; a missing or broken record earns nothing.
- DMARC policy — up to 25.
p=rejectearns 25,p=quarantine15,p=none5. This is the largest single lever on the page. - DMARC reporting — 10. An
rua=address earns the full 10. Enforcing a policy with nowhere to send reports means rejecting mail blind, so a policy withoutrua=is flagged as a finding. - SPF — up to 20. A valid record earns 15 (10 fewer if it warns), plus 5 for ending in
-allor 3 for~all. Exceeding the ten-lookup limit subtracts 10 on top. - DKIM — up to 15. A key found under any probed selector earns 15.
- MX — 5. Records present.
One penalty sits outside that budget, because it is reputation rather than configuration and can only ever subtract. A listed mail server takes 15 points off whatever the configuration earned. Often that is a shared-IP neighbour rather than you, but it drags the domain's reputation down all the same, and a score that hid it would be lying to you.
How to read your band
75 and above means the authentication story is sound: filters can verify you, and a spoofer can't easily impersonate you. 45 to 74 means the records exist but stop short — usually p=none, a missing rua=, or an SPF record that softfails. Below 45 means a filter has little to go on, and your mail is competing on content alone against everything else in the queue.
The findings under the score are ordered so the top one is the biggest single improvement available. Fix that, re-check, and the number moves.
The three fixes that move the number most
1. Publish DMARC — then get off p=none
Half the available points live in the DMARC section, and that is not an arbitrary weighting: DMARC is the only one of these mechanisms that tells a receiver what to do when authentication fails. Without it, an unauthenticated message forging your domain is handled at each receiver's discretion, and plenty of them will deliver it.
Publishing p=none earns 5 of 25 for a reason. Monitor-only is where you start, not where you stop — it collects evidence and blocks nothing. Read your reports until every legitimate sender passes, then move to p=quarantine and on to p=reject. Choosing a DMARC policy walks the staged rollout, and the DMARC record checker validates the syntax before you publish it.
2. Get DKIM signing, and keep it signed
DKIM is worth 15 points here and considerably more than that in practice, because it is the only one of the two authentication mechanisms that survives forwarding. SPF breaks the instant a message is relayed by a server you never listed — and forwarding is entirely outside your control. Since DMARC passes when either SPF or DKIM aligns, a domain signing with DKIM has two independent chances for real mail to authenticate. Domains relying on SPF alone are the ones whose forwarded mail lands in spam for no apparent reason. If the check reports no key, confirm with the DKIM checker first: a custom selector is invisible to any probe, so the key may be there and simply unfindable.
3. Repair the SPF record you already have
SPF failures are rarely absences — they are records that quietly stopped working. Ten DNS lookups is a hard protocol limit, and every include: you add for a new marketing platform spends from that budget; go over it and receivers return a permanent error and stop evaluating the record entirely, which is worse than having published nothing. Two SPF records on one domain is the same class of fault. The SPF record checker counts the lookups and names which includes cost the most, and how SPF works explains the mechanism behind the count.
Common questions
Why doesn't this send a test email?
Because a send-test tells you about one message to one mailbox at one moment, and the result changes with the recipient, the sending IP's warmth that day, and the content of that particular message. The signals here are stable properties of your domain that apply to every message you send. It's also worth stating plainly: if these checks fail, a test email won't land in the inbox either — you'd just be paying for a slower way to learn the same thing.
Can I score 100 and still land in spam?
Yes. Authentication is the entry requirement, not the whole exam. Sending to stale lists, sudden volume spikes from a cold IP, missing unsubscribe headers, and a poor complaint rate will sink well-authenticated mail. What a high score buys you is that none of your deliverability problems are authentication problems — which removes the most common cause and makes the rest diagnosable.
My score dropped and I changed nothing. What happened?
Something changed in DNS that you didn't make: a provider rotated a DKIM key, an include: in your SPF record grew and pushed you past the lookup limit, or one of your mail servers picked up a blocklist listing. This is the ordinary case, not the exception — DNS drift is why a one-off check has a short shelf life.
Does the checker see anything private?
No. Every record it reads is public DNS that any receiving mail server looks up before accepting your mail. Nothing here requires access to your mailbox, your provider account, or your message content.
What should I do after fixing everything?
Point your DMARC rua= at a monitor and read what comes back. The reports name every server sending as your domain — including the ones you forgot about and the ones that were never yours. If you already have a report to hand, the DMARC report analyzer turns the XML into a readable table without an account. What DMARC reports contain covers the format itself.