About
Most DNS tools show you your records and leave the hard part to you: whether they are right, whether a tag combination is dangerous, and whether the RFC you are reading is still current. I wanted a tool that did the analysis, showed its work, cited the RFC it checked against, and gave me the exact record to paste. I could not find one, so I built it.
Enter a domain and it reads the public DNS records behind your email and the policy files they point to, then tells you what is missing or misconfigured and how to fix it. DMARC is checked two ways: against RFC 9989, the standard published in May 2026 alongside RFC 9990 for aggregate reporting and RFC 9991 for failure reporting, and against the RFC 7489 behavior most receivers still run while tree walk support rolls out. You see both results and what changes between them. SPF, DKIM, MX, DNSSEC, MTA-STS, TLS-RPT, DANE, CAA, BIMI, Certificate Transparency, and nameserver configuration are covered as well.
It's free. There are no accounts, no cookies, and no tracking. The code is open source under the MIT License; you can read it, run it yourself, or fork it.
Who built this
I'm Neil Anuskiewicz, and I've worked in email from Eugene, Oregon since 2004. That started with twelve years at StreamSend, an email service provider, the last seven as a solutions engineer working on authentication and deliverability for its customers. Before that I was the hostmaster at an ISP, and I wrote about DNS for Linux Journal in 2001.
At Proofpoint Professional Services I deployed email security and email fraud defense for more than 40 enterprise customers and led DMARC programs from p=none to p=reject without disrupting legitimate mail. Most of the judgment in this tool comes from that work: what a real rollout breaks, and which failures are worth acting on.
Between and since those jobs I've worked independently, with more than 180 contracts on Upwork, most of them deliverability work. My clients are mostly small businesses, nonprofits, MSPs, and startups on Google Workspace or Microsoft 365, and the job is usually the same one at a smaller scale.
If your audit turned up something
Some findings are a five-minute DNS change. Others are not, and the hard part is telling which is which before you touch anything.
If you want a second opinion, email [email protected] or message me on LinkedIn with your domain. I'll read the audit and tell you plainly whether it needs a consultant or a careful hour of your own time. When it needs one, the work is scoped in writing before anything starts. The scope says what is wrong and what the change is, and it names anything that could break. You approve it and we make the change together. Longer work, such as taking a domain with a dozen sending services to DMARC enforcement, is scoped the same way.