Check email authentication
check_email_authRead-onlyIdempotent
Explain in plain words whether email from a domain will reach the inbox and whether others can forge it. Checks MX, SPF with every include expanded and counted against the 10-lookup limit, DMARC policy, alignment and report permissions, DKIM keys at about 40 common selectors plus any you name (with key size), BIMI, MTA-STS and TLS-RPT, and the DNS rules Google, Yahoo and Microsoft set for bulk senders. Every finding has a severity, a one-sentence fix and the RFC or provider document behind it. Reads public DNS only.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| detail | No | "summary" (default) lists only findings that need action; "full" also lists every passing check. | summary |
| domain | Yes | The domain to check, such as example.com. A website address (https://www.example.com/page) or an email address (jo@example.com) also works; the domain is taken from it. | |
| dkim_selectors | No | Extra DKIM selectors to check, such as the s= value from a DKIM-Signature header (for example "s1" or "selector1"). About 40 common selectors are always checked. |