SPF, DKIM and DMARC check
SPF, DKIM and DMARC for your domain: what is missing, what is wrong and the exact record that fixes it.
FREE TOOL
The domain's registrar, DNS, host, mail, certificate and platform on one map. Under it: what to ask for if you have no access.
We never show the holder's name or contact details, even when the registry returns them. You can reach the holder through the registrar.
We take over sites we did not build, after a review.
Replace your text with the result?
A copy is on its way to your inbox. If it does not arrive, check the spam folder — and write to us directly. [email protected]
Reference number:
We ask the registry for the registrar over RDAP, and read DNS, the host and the mail from the public DNS records and RIPE NCC's public network data (RIPEstat). We see the certificate the way every browser sees it, and the platform on the home page, only when the page says so itself. We open no other page and never show the holder's name.
We only look at what the site shows every visitor and at the domain's public records. We do not try passwords, forms or hidden addresses.
The service behind this check: website maintenance.
In the glossary: Web hosting · Content delivery network (CDN)
IF YOU HAVE NO ACCESS
This is not legal advice.
The domain belongs to the holder on the registry's record, and the registrar acts on documents. Ask it to put the domain's management in your name, with a document showing that the company or the domain is yours.
A hosting provider gives access only to the account holder. If the account is in the name of the company that built your site, the transfer goes through that company or through the documents you paid with.
In writing, not on the phone:
Having paid does not by itself make the code and the data yours; it depends on the contract. The ownership question is in the guide how to choose a web development company.
A lawyer can write to them on your behalf.
QUESTIONS
Type the site's address. The check reads the public DNS records, finds the network the server sits in from RIPE NCC's public data, and names the provider. If the site sits behind Cloudflare or a similar service, the real host cannot be seen from outside; look it up in the domain's control panel or ask whoever built the site.
Start with the map here: which registrar holds the domain and which provider hosts the site. The registrar and the host give access to the account holder on the strength of documents. Then ask the company in writing for the access listed on this page. If that does not work, a lawyer.
It depends on the contract. The domain belongs to whoever it is registered to, the hosting to the account holder, and the code and data to whoever the contract says. Ask in writing for confirmation of what is in whose name, and for a dispute, see a lawyer.
Cloudflare stands between visitors and the server: it protects the site and speeds it up, but shows its own addresses instead of the server's. That is why the real host cannot be seen from outside. You can see it in the Cloudflare account and in the hosting control panel.
SPF, DKIM and DMARC for your domain: what is missing, what is wrong and the exact record that fixes it.
When the certificate expires, who issued it and whether the chain is complete, with a reminder for your calendar.