Canny Pigeons
Free tool

Email spam checker

Enter a domain and we'll score how much spam filters trust it — DMARC policy strength, SPF validity, DKIM signatures and MX records, read live from DNS. A free spam test without sending a single email.

What this spam checker actually tests

Most tools called a "spam test" ask you to send a message to a throwaway address and then grade the result. That measures one delivery, once, from one server. This one measures something more durable: how much of your domain's trust is established before a message is ever sent.

Every signal below is read live from public DNS the moment you press Check — nothing is cached, nothing is inferred from a previous visitor's lookup, and no email leaves your mail server:

These are the signals a receiving filter can evaluate on its own, without ever having seen your domain before. Content heuristics — spammy phrasing, image-to-text ratio, link reputation — matter too, but they matter after authentication. A domain that fails authentication starts every message from a deficit no subject line can recover.

How the score is calculated

The scale is published rather than proprietary, because a number you can't reconstruct is a number you can't act on. One hundred points are distributed across the signals filters actually weigh:

One penalty sits outside that budget, because it is reputation rather than configuration and can only ever subtract. A listed mail server takes 15 points off whatever the configuration earned. Often that is a shared-IP neighbour rather than you, but it drags the domain's reputation down all the same, and a score that hid it would be lying to you.

How to read your band

75 and above means the authentication story is sound: filters can verify you, and a spoofer can't easily impersonate you. 45 to 74 means the records exist but stop short — usually p=none, a missing rua=, or an SPF record that softfails. Below 45 means a filter has little to go on, and your mail is competing on content alone against everything else in the queue.

The findings under the score are ordered so the top one is the biggest single improvement available. Fix that, re-check, and the number moves.

The three fixes that move the number most

1. Publish DMARC — then get off p=none

Half the available points live in the DMARC section, and that is not an arbitrary weighting: DMARC is the only one of these mechanisms that tells a receiver what to do when authentication fails. Without it, an unauthenticated message forging your domain is handled at each receiver's discretion, and plenty of them will deliver it.

Publishing p=none earns 5 of 25 for a reason. Monitor-only is where you start, not where you stop — it collects evidence and blocks nothing. Read your reports until every legitimate sender passes, then move to p=quarantine and on to p=reject. Choosing a DMARC policy walks the staged rollout, and the DMARC record checker validates the syntax before you publish it.

2. Get DKIM signing, and keep it signed

DKIM is worth 15 points here and considerably more than that in practice, because it is the only one of the two authentication mechanisms that survives forwarding. SPF breaks the instant a message is relayed by a server you never listed — and forwarding is entirely outside your control. Since DMARC passes when either SPF or DKIM aligns, a domain signing with DKIM has two independent chances for real mail to authenticate. Domains relying on SPF alone are the ones whose forwarded mail lands in spam for no apparent reason. If the check reports no key, confirm with the DKIM checker first: a custom selector is invisible to any probe, so the key may be there and simply unfindable.

3. Repair the SPF record you already have

SPF failures are rarely absences — they are records that quietly stopped working. Ten DNS lookups is a hard protocol limit, and every include: you add for a new marketing platform spends from that budget; go over it and receivers return a permanent error and stop evaluating the record entirely, which is worse than having published nothing. Two SPF records on one domain is the same class of fault. The SPF record checker counts the lookups and names which includes cost the most, and how SPF works explains the mechanism behind the count.

Common questions

Why doesn't this send a test email?

Because a send-test tells you about one message to one mailbox at one moment, and the result changes with the recipient, the sending IP's warmth that day, and the content of that particular message. The signals here are stable properties of your domain that apply to every message you send. It's also worth stating plainly: if these checks fail, a test email won't land in the inbox either — you'd just be paying for a slower way to learn the same thing.

Can I score 100 and still land in spam?

Yes. Authentication is the entry requirement, not the whole exam. Sending to stale lists, sudden volume spikes from a cold IP, missing unsubscribe headers, and a poor complaint rate will sink well-authenticated mail. What a high score buys you is that none of your deliverability problems are authentication problems — which removes the most common cause and makes the rest diagnosable.

My score dropped and I changed nothing. What happened?

Something changed in DNS that you didn't make: a provider rotated a DKIM key, an include: in your SPF record grew and pushed you past the lookup limit, or one of your mail servers picked up a blocklist listing. This is the ordinary case, not the exception — DNS drift is why a one-off check has a short shelf life.

Does the checker see anything private?

No. Every record it reads is public DNS that any receiving mail server looks up before accepting your mail. Nothing here requires access to your mailbox, your provider account, or your message content.

What should I do after fixing everything?

Point your DMARC rua= at a monitor and read what comes back. The reports name every server sending as your domain — including the ones you forgot about and the ones that were never yours. If you already have a report to hand, the DMARC report analyzer turns the XML into a readable table without an account. What DMARC reports contain covers the format itself.

Also free: DMARC checker · SPF record checker · DKIM checker · DMARC report analyzer