Email Analysis — Check Your Email Security

Test your email configuration in seconds. This free mail tester checks SPF, DKIM, DMARC, 43 blacklists, encryption and over 20 further checks — just send an email and get a detailed report.

Three steps to your report

1

Send an email

Send or forward any email to hello@analyzemy.email

2

Get the report

You'll instantly receive a reply with your security score

3

View the details

Click the link for the full analysis

20+
Security Checks
43
IP Blacklists
0-100
Security Score
<30s
Analysis time

Rather not send an email? Check and build right in your browser

These tools work purely from what your domain publishes in DNS — enter a domain name, get the result instantly. Whatever only a real message can reveal stays with the email analysis.

Or build a record from scratch

The generators load an existing record into the form and run the finished draft through the same audit as the checking tools.

All tools at a glance →

Check email security — all checks at a glance

Every incoming email automatically runs through more than 20 checks — from the SPF check to the blacklist test to header analysis. Each check is explained individually.

SPF

SPF Check

Validates your domain's SPF TXT record and whether the sending server is authorized — including a full audit of the record against RFC 7208.

IP

SPF IP Analysis

Why every IP in your SPF record matters — the report resolves them all recursively and checks each for blacklist entries, reverse DNS, FCrDNS and ASN ownership.

DKIM

DKIM Check

How DKIM signs outgoing mail — the report verifies every signature in the message against the key in DNS and checks alignment with the From header.

DMARC

DMARC Check

Validates the DMARC record, evaluates SPF and DKIM alignment, and audits the policy for weaknesses — from p=none through pct to the subdomain policy.

ARC

ARC Chain Validation

How ARC carries authentication across forwarding, where SPF fails by design — the report evaluates the Authenticated Received Chain per RFC 8617.

ENV

Envelope-From vs Header-From

Why every email has two senders — the report compares the Return-Path address with the visible From header. A mismatch breaks SPF alignment.

LOOK

SPF Lookup Limit

How the ten-lookup limit is counted — the report counts your SPF record's DNS lookups recursively across every include and redirect chain, with the sublimits for void lookups, mx and ptr.

KEY

DKIM Key Strength

Why a passing signature is not necessarily a good one — the report breaks the DKIM signature down into selector, algorithm, key length, signed headers and the l= tag.

RUA

DMARC Report Destinations

Why DMARC reports sent to an external domain need authorization via a _report._dmarc record — the report checks this for every external rua and ruf destination.

TLS

TLS Transport Analysis

How TLS protects email in transit — the report reads TLS version, cipher suite and key strength from the Received headers and shows the status per hop.

STS

MTA-STS Check

How MTA-STS enforces TLS for inbound mail with a DNS record and a policy file — and what the report evaluates on mode, MX patterns and validity period.

DANE

DANE / TLSA

How DANE anchors a mail server's certificate in DNS via DNSSEC — the report checks the TLSA records of the sender domain's MX hosts.

CERT

MX TLS Certificate

What matters in a mail server's TLS certificate — the report opens a real STARTTLS connection to the sender domain's MX servers and inspects the certificate from chain to expiry.

SMTP

STARTTLS Support

How STARTTLS upgrades an SMTP connection to encryption — the report connects to the sender domain's MX servers and checks whether STARTTLS is offered in the EHLO response.

RPT

TLS-RPT Check

How TLS-RPT reports failed encrypted deliveries to you — the report checks the record at _smtp._tls and the reporting address behind it.

BL

IP Blacklist Check

Checks the sending IP against 43 DNS blacklists in parallel — from Spamhaus ZEN to SpamCop and SpamRATS — and shows the return codes of every listing.

DBL

Domain Blacklist Check

Checks the sender domain against 15 domain-based blacklists. Domain reputation applies independently of the sending IP.

URL

URL Blacklist Check

How spam filters rate links — the report extracts the domains of all links in the email body and checks them against URI blacklists.

IDN

Homograph / IDN Detection

Detects domains with mixed scripts and confusable characters in the sender and links — the technique behind IDN homograph phishing.

127

DNSBL Return Codes

Evaluates the A record returned by each blacklist and separates genuine listings from informational codes and rejected queries.

ASN

ASN and Network Owner

Who owns the sending IP and why it matters — the report resolves AS number, operator, country and registry for every IP, the sending IP as well as each in the SPF record.

BULK

Bulk Sender Checklist

Turns the requirements Gmail, Yahoo and Microsoft place on bulk senders into a checklist and checks every point that can be read from a single delivered message.

ATT

Attachment Analysis

Which attachments carry malware — the report detects dangerous file types, double extensions and macro-enabled Office documents.

BODY

Body & Spam Analysis

What spam filters actually score in the message body — the report looks for missing plaintext, tracking pixels, hidden text, shorteners and the image-to-text ratio.

LINK

Link Verification

Why links in email break so often — the report calls every link in the message body and reports dead links, redirect chains, status codes and SSL errors.

HDR

Header Analysis

What an email's headers reveal — the report checks them SpamAssassin-style: Message-ID, date, MIME-Version, Reply-To mismatch, duplicate From headers, X-Mailer and subject.

RCVD

Reading Received Headers

Breaks the Received chain into individual hops with timestamp, server name and encryption status, and derives the actually sending IP address from it.

MIME

MIME Structure

How an email is put together — the report breaks down its MIME structure: content type, which parts exist, the order of text and HTML, and the text-to-image ratio.

UNSUB

List-Unsubscribe & One-Click

When one-click unsubscribe per RFC 8058 applies — the report checks a real message's unsubscribe addresses, the Post header and whether a valid DKIM signature covers both headers.

PHISH

Phishing Indicators

Looks for the traits phishing mail uses to disguise its sender and link targets: in the display name, the reply address and the links. Indicators, not proof.

DNS

MX Record Analysis

Resolves the domain's MX records and analyzes each MX host individually — A records, reverse DNS and FCrDNS.

rDNS

HELO / rDNS Match

How receivers match the HELO/EHLO hostname against the sending IP's reverse DNS. A mismatch is one of the most common rejection reasons at large providers.

BIMI

BIMI Check

How BIMI puts your brand logo in the inbox — the report shows whether a BIMI record exists and which logo URL it names. It requires an enforced DMARC policy.

FCr

FCrDNS Check

Resolves an IP's PTR record, looks the resulting hostname up again in the forward direction and checks whether the original IP comes back.

Guides — fix the problems directly

Step-by-step instructions for the most common gaps in an email setup.

Email testing — why it matters

A misconfigured email domain causes messages to land in spam or get rejected entirely. With this free email analysis you can test your deliverability and spot problems instantly.

The mail tester performs a complete SPF check, DKIM check and DMARC check. Your sending IP is additionally tested against 43 blacklists, and a spam test is derived from header analysis, encryption and DNS configuration.

Want to test your email configuration or check your mail server? Just send an email to hello@analyzemy.email. Within seconds you receive an email score and a detailed report with every result — including header analysis, email authentication and a blacklist check.

If a record is missing entirely, you do not have to type it by hand: the SPF generator lets you create an SPF record or rebuild an existing one — including a recursive count of its DNS lookups against the limit of ten, before the record ever reaches DNS. The DMARC generator helps you create a DMARC record: policy, reporting address and alignment in a form, plus a pointer to which rollout step comes next. Both load an existing record and show tag by tag what changes.

Since 2024, Google and Yahoo require proper email authentication (SPF + DKIM + DMARC) from all senders. Check now whether your domain meets the requirements.

Privacy
We only store technical metadata (headers, DNS records, IPs). Email contents and attachments are not stored.
Analyze my email now