What does this cold email domain checker test?
It asks public DNS for the four records a receiving server looks at before it trusts mail from your domain. Each one gets a pass, a check or a fix.
| Record | What it proves | What happens without it |
|---|---|---|
| MX | The domain can receive mail | Replies and bounces have nowhere to go |
| SPF | Which servers may send as the domain | Receivers cannot tell your mail from a forgery |
| DKIM | The message was signed by the domain and not changed | No signature to align with DMARC |
| DMARC | What receivers should do when SPF and DKIM fail, and where to send reports | Google and Yahoo treat bulk mail without it as suspect |
Why does the checker say it could not find my DKIM key?
DNS has no way to list a domain's DKIM keys. A key lives at a name made of a selector, such as google._domainkey.yourcompany.com, and the selector is chosen by whoever signs your mail. The checker tries the selectors the common mailbox hosts use. If yours is different, open an email you sent, find the s= value in its DKIM-Signature header, and enter it as the selector. Our guide to what DKIM is shows where to look.
What score should a cold email domain get?
Four out of four before it sends a single cold email. A "check" on DMARC with no reports address is not dangerous, but the reports are how you find out that SPF or DKIM broke. A fix on SPF, DKIM or MX means mail from the domain will fail authentication or lose its replies, so sort that first. If a record is right but email still fails, our guide to fixing DMARC fail covers alignment, the cause the records alone do not show.
Should I check my main domain or my cold email domain?
Both, but they should not be the same domain. Cold email belongs on separate sending domains, so a complaint or a spam-trap hit lands on a domain you can replace instead of the one your clients and invoices use. Our guide to sending domains explains the setup.
Does this cold email checker store my domain?
No. The check runs live against public DNS and the result is shown to you only. We count checks per visitor to stop automated scanning, using a one-way hash that expires within the hour, and we do not keep the domain you typed.