Check a domain's email authentication (SPF, DKIM, DMARC, BIMI, MX, MTA-STS, TLS-RPT)
check_domainRead-onlyIdempotent
Audit the email-authentication DNS records of a domain. Returns a 0–100 score and A–F grade (MX 10, SPF 25, DMARC 30, DKIM 25, BIMI 10, plus up to 5 bonus points for MTA-STS and TLS-RPT, capped at 100), each check's status, published record, findings and recommended fixes, and a link to the full report. Read-only: it only queries public DNS and the domain's public MTA-STS policy file. Same engine and scoring as the DnsGuard JSON API (GET /api/check).
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | Domain to check, e.g. example.com. A URL or email address is accepted and reduced to its domain. | |
| include_raw | No | Also return the full /api/check JSON (all records, SPF include tree, DKIM keys) in structuredContent.raw. Larger output. | |
| dkim_selector | No | Optional DKIM selector (the s= value from a DKIM-Signature header), e.g. s1 or google. Common selectors are always tried. |
Output Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| raw | No | Full /api/check response (only when include_raw is true) | |
| tier | No | ||
| grade | Yes | ||
| notes | No | ||
| score | Yes | ||
| apiUrl | No | ||
| cached | No | ||
| checks | Yes | ||
| domain | Yes | ||
| version | No | ||
| maxScore | Yes | ||
| checkedAt | No | ||
| reportUrl | Yes | ||
| scoreBreakdown | No | ||
| organizationalDomain | No |