SPF
Who may send
A TXT record listing the servers allowed to send as your domain. We check that it exists, that it is unique, that it ends with the right policy (-all or ~all) and that it stays under the 10-lookup limit.
Free tool
Enter a domain and see what receivers see: the SPF record, the DKIM keys, the DMARC policy — with the problems named, not just listed.
No signup, nothing stored — the check runs live against public DNS.
What we check
SPF
A TXT record listing the servers allowed to send as your domain. We check that it exists, that it is unique, that it ends with the right policy (-all or ~all) and that it stays under the 10-lookup limit.
DKIM
A public key published at a selector of your provider's choosing. We try the common selectors, verify that the key is not empty, and follow CNAME-based setups to the real key.
DMARC
The policy receivers apply when SPF or DKIM fail: none, quarantine or reject — plus reporting addresses. We read the tags and tell you what the policy actually means in practice.
Full guide: how to read these results, and what to fix first.
Available now
TOM configures SPF, DKIM and DMARC when you create a mailbox — and paces the sending that follows: progressive warmup, per-address checks, sending windows in the prospect's time.