Email Analysis — Check Your Email Security
Test your email configuration in seconds. This free mail tester checks SPF, DKIM, DMARC, 43 blacklists, encryption and over 20 further checks — just send an email and get a detailed report.
Three steps to your report
Send an email
Send or forward any email to hello@analyzemy.email
Get the report
You'll instantly receive a reply with your security score
View the details
Click the link for the full analysis
Rather not send an email? Check and build right in your browser
These tools work purely from what your domain publishes in DNS — enter a domain name, get the result instantly. Whatever only a real message can reveal stays with the email analysis.
SPF Record Lookup
Checks syntax, lookup limit and the all qualifier of an SPF record.
DMARC Record Lookup
Policy, alignment, reporting and external report authorization.
Blacklist Check
Domain, mail server name or IP — against 43 DNSBLs and 15 domain BLs.
MX Record Lookup
MX records, rDNS/FCrDNS, STARTTLS, certificate and DANE.
DKIM Record Lookup
Look up a selector, or probe the ones the big providers use.
MTA-STS Policy Test
Record, policy file, and the match against your real MX hosts.
BIMI Record Test
Record, logo file and the DMARC prerequisite in one pass.
Reverse DNS Check
PTR, the forward confirmation and the network operator per address.
Or build a record from scratch
The generators load an existing record into the form and run the finished draft through the same audit as the checking tools.
Check email security — all checks at a glance
Every incoming email automatically runs through more than 20 checks — from the SPF check to the blacklist test to header analysis. Each check is explained individually.
SPF Check
Validates your domain's SPF TXT record and whether the sending server is authorized — including a full audit of the record against RFC 7208.
SPF IP Analysis
Why every IP in your SPF record matters — the report resolves them all recursively and checks each for blacklist entries, reverse DNS, FCrDNS and ASN ownership.
DKIM Check
How DKIM signs outgoing mail — the report verifies every signature in the message against the key in DNS and checks alignment with the From header.
DMARC Check
Validates the DMARC record, evaluates SPF and DKIM alignment, and audits the policy for weaknesses — from p=none through pct to the subdomain policy.
ARC Chain Validation
How ARC carries authentication across forwarding, where SPF fails by design — the report evaluates the Authenticated Received Chain per RFC 8617.
Envelope-From vs Header-From
Why every email has two senders — the report compares the Return-Path address with the visible From header. A mismatch breaks SPF alignment.
SPF Lookup Limit
How the ten-lookup limit is counted — the report counts your SPF record's DNS lookups recursively across every include and redirect chain, with the sublimits for void lookups, mx and ptr.
DKIM Key Strength
Why a passing signature is not necessarily a good one — the report breaks the DKIM signature down into selector, algorithm, key length, signed headers and the l= tag.
DMARC Report Destinations
Why DMARC reports sent to an external domain need authorization via a _report._dmarc record — the report checks this for every external rua and ruf destination.
TLS Transport Analysis
How TLS protects email in transit — the report reads TLS version, cipher suite and key strength from the Received headers and shows the status per hop.
MTA-STS Check
How MTA-STS enforces TLS for inbound mail with a DNS record and a policy file — and what the report evaluates on mode, MX patterns and validity period.
DANE / TLSA
How DANE anchors a mail server's certificate in DNS via DNSSEC — the report checks the TLSA records of the sender domain's MX hosts.
MX TLS Certificate
What matters in a mail server's TLS certificate — the report opens a real STARTTLS connection to the sender domain's MX servers and inspects the certificate from chain to expiry.
STARTTLS Support
How STARTTLS upgrades an SMTP connection to encryption — the report connects to the sender domain's MX servers and checks whether STARTTLS is offered in the EHLO response.
TLS-RPT Check
How TLS-RPT reports failed encrypted deliveries to you — the report checks the record at _smtp._tls and the reporting address behind it.
IP Blacklist Check
Checks the sending IP against 43 DNS blacklists in parallel — from Spamhaus ZEN to SpamCop and SpamRATS — and shows the return codes of every listing.
Domain Blacklist Check
Checks the sender domain against 15 domain-based blacklists. Domain reputation applies independently of the sending IP.
URL Blacklist Check
How spam filters rate links — the report extracts the domains of all links in the email body and checks them against URI blacklists.
Homograph / IDN Detection
Detects domains with mixed scripts and confusable characters in the sender and links — the technique behind IDN homograph phishing.
DNSBL Return Codes
Evaluates the A record returned by each blacklist and separates genuine listings from informational codes and rejected queries.
ASN and Network Owner
Who owns the sending IP and why it matters — the report resolves AS number, operator, country and registry for every IP, the sending IP as well as each in the SPF record.
Bulk Sender Checklist
Turns the requirements Gmail, Yahoo and Microsoft place on bulk senders into a checklist and checks every point that can be read from a single delivered message.
Attachment Analysis
Which attachments carry malware — the report detects dangerous file types, double extensions and macro-enabled Office documents.
Body & Spam Analysis
What spam filters actually score in the message body — the report looks for missing plaintext, tracking pixels, hidden text, shorteners and the image-to-text ratio.
Link Verification
Why links in email break so often — the report calls every link in the message body and reports dead links, redirect chains, status codes and SSL errors.
Header Analysis
What an email's headers reveal — the report checks them SpamAssassin-style: Message-ID, date, MIME-Version, Reply-To mismatch, duplicate From headers, X-Mailer and subject.
Reading Received Headers
Breaks the Received chain into individual hops with timestamp, server name and encryption status, and derives the actually sending IP address from it.
MIME Structure
How an email is put together — the report breaks down its MIME structure: content type, which parts exist, the order of text and HTML, and the text-to-image ratio.
List-Unsubscribe & One-Click
When one-click unsubscribe per RFC 8058 applies — the report checks a real message's unsubscribe addresses, the Post header and whether a valid DKIM signature covers both headers.
Phishing Indicators
Looks for the traits phishing mail uses to disguise its sender and link targets: in the display name, the reply address and the links. Indicators, not proof.
MX Record Analysis
Resolves the domain's MX records and analyzes each MX host individually — A records, reverse DNS and FCrDNS.
HELO / rDNS Match
How receivers match the HELO/EHLO hostname against the sending IP's reverse DNS. A mismatch is one of the most common rejection reasons at large providers.
BIMI Check
How BIMI puts your brand logo in the inbox — the report shows whether a BIMI record exists and which logo URL it names. It requires an enforced DMARC policy.
FCrDNS Check
Resolves an IP's PTR record, looks the resulting hostname up again in the forward direction and checks whether the original IP comes back.
Guides — fix the problems directly
Step-by-step instructions for the most common gaps in an email setup.
Email testing — why it matters
A misconfigured email domain causes messages to land in spam or get rejected entirely. With this free email analysis you can test your deliverability and spot problems instantly.
The mail tester performs a complete SPF check, DKIM check and DMARC check. Your sending IP is additionally tested against 43 blacklists, and a spam test is derived from header analysis, encryption and DNS configuration.
Want to test your email configuration or check your mail server? Just send an email to hello@analyzemy.email. Within seconds you receive an email score and a detailed report with every result — including header analysis, email authentication and a blacklist check.
If a record is missing entirely, you do not have to type it by hand: the SPF generator lets you create an SPF record or rebuild an existing one — including a recursive count of its DNS lookups against the limit of ten, before the record ever reaches DNS. The DMARC generator helps you create a DMARC record: policy, reporting address and alignment in a form, plus a pointer to which rollout step comes next. Both load an existing record and show tag by tag what changes.
Since 2024, Google and Yahoo require proper email authentication (SPF + DKIM + DMARC) from all senders. Check now whether your domain meets the requirements.
We only store technical metadata (headers, DNS records, IPs). Email contents and attachments are not stored.