AUTHENTICATION

Authentication

Who may send on behalf of your domain — and can it be proven?

SPF Check DNS + IP

Validates your domain's SPF TXT record and whether the sending server is authorized — including a full audit of the record against RFC 7208.

SPF IP Analysis DNS + BL

Why every IP in your SPF record matters — the report resolves them all recursively and checks each for blacklist entries, reverse DNS, FCrDNS and ASN ownership.

DKIM Check CRYPTO

How DKIM signs outgoing mail — the report verifies every signature in the message against the key in DNS and checks alignment with the From header.

DMARC Check DNS + POLICY

Validates the DMARC record, evaluates SPF and DKIM alignment, and audits the policy for weaknesses — from p=none through pct to the subdomain policy.

ARC Chain Validation FORWARDING

How ARC carries authentication across forwarding, where SPF fails by design — the report evaluates the Authenticated Received Chain per RFC 8617.

Envelope-From vs Header-From SPOOFING

Why every email has two senders — the report compares the Return-Path address with the visible From header. A mismatch breaks SPF alignment.

SPF Lookup Limit 10 LOOKUPS

How the ten-lookup limit is counted — the report counts your SPF record's DNS lookups recursively across every include and redirect chain, with the sublimits for void lookups, mx and ptr.

DKIM Key Strength RSA/ED25519

Why a passing signature is not necessarily a good one — the report breaks the DKIM signature down into selector, algorithm, key length, signed headers and the l= tag.

DMARC Report Destinations RUA + RUF

Why DMARC reports sent to an external domain need authorization via a _report._dmarc record — the report checks this for every external rua and ruf destination.

TRANSPORT

Transport Security

Encryption on the way from server to server.

TLS Transport Analysis ENCRYPTION

How TLS protects email in transit — the report reads TLS version, cipher suite and key strength from the Received headers and shows the status per hop.

MTA-STS Check DNS + HTTPS

How MTA-STS enforces TLS for inbound mail with a DNS record and a policy file — and what the report evaluates on mode, MX patterns and validity period.

DANE / TLSA DNSSEC

How DANE anchors a mail server's certificate in DNS via DNSSEC — the report checks the TLSA records of the sender domain's MX hosts.

MX TLS Certificate STARTTLS

What matters in a mail server's TLS certificate — the report opens a real STARTTLS connection to the sender domain's MX servers and inspects the certificate from chain to expiry.

STARTTLS Support SMTP

How STARTTLS upgrades an SMTP connection to encryption — the report connects to the sender domain's MX servers and checks whether STARTTLS is offered in the EHLO response.

TLS-RPT Check REPORTING

How TLS-RPT reports failed encrypted deliveries to you — the report checks the record at _smtp._tls and the reporting address behind it.

REPUTATION

Reputation & Blacklists

How your IP, domain and links stand with the major filter lists.

IP Blacklist Check 43 LISTEN

Checks the sending IP against 43 DNS blacklists in parallel — from Spamhaus ZEN to SpamCop and SpamRATS — and shows the return codes of every listing.

Domain Blacklist Check 15 LISTEN

Checks the sender domain against 15 domain-based blacklists. Domain reputation applies independently of the sending IP.

URL Blacklist Check 5 LISTEN

How spam filters rate links — the report extracts the domains of all links in the email body and checks them against URI blacklists.

Homograph / IDN Detection PHISHING

Detects domains with mixed scripts and confusable characters in the sender and links — the technique behind IDN homograph phishing.

DNSBL Return Codes RETURN CODES

Evaluates the A record returned by each blacklist and separates genuine listings from informational codes and rejected queries.

ASN and Network Owner NETWORK

Who owns the sending IP and why it matters — the report resolves AS number, operator, country and registry for every IP, the sending IP as well as each in the SPF record.

Bulk Sender Checklist GMAIL/YAHOO

Turns the requirements Gmail, Yahoo and Microsoft place on bulk senders into a checklist and checks every point that can be read from a single delivered message.

CONTENT

Content & Attachments

What spam filters evaluate in the message body and attachments.

Attachment Analysis MALWARE

Which attachments carry malware — the report detects dangerous file types, double extensions and macro-enabled Office documents.

Body & Spam Analysis SPAM

What spam filters actually score in the message body — the report looks for missing plaintext, tracking pixels, hidden text, shorteners and the image-to-text ratio.

Link Verification HTTP

Why links in email break so often — the report calls every link in the message body and reports dead links, redirect chains, status codes and SSL errors.

Header Analysis METADATA

What an email's headers reveal — the report checks them SpamAssassin-style: Message-ID, date, MIME-Version, Reply-To mismatch, duplicate From headers, X-Mailer and subject.

Reading Received Headers ROUTING

Breaks the Received chain into individual hops with timestamp, server name and encryption status, and derives the actually sending IP address from it.

MIME Structure STRUCTURE

How an email is put together — the report breaks down its MIME structure: content type, which parts exist, the order of text and HTML, and the text-to-image ratio.

List-Unsubscribe & One-Click RFC 8058

When one-click unsubscribe per RFC 8058 applies — the report checks a real message's unsubscribe addresses, the Post header and whether a valid DKIM signature covers both headers.

Phishing Indicators INDICATORS

Looks for the traits phishing mail uses to disguise its sender and link targets: in the display name, the reply address and the links. Indicators, not proof.

INFRASTRUCTURE

DNS & Infrastructure

MX records, reverse DNS and the basics of server reputation.

MX Record Analysis DNS

Resolves the domain's MX records and analyzes each MX host individually — A records, reverse DNS and FCrDNS.

HELO / rDNS Match SMTP

How receivers match the HELO/EHLO hostname against the sending IP's reverse DNS. A mismatch is one of the most common rejection reasons at large providers.

BIMI Check BRANDING

How BIMI puts your brand logo in the inbox — the report shows whether a BIMI record exists and which logo URL it names. It requires an enforced DMARC policy.

FCrDNS Check PTR + A

Resolves an IP's PTR record, looks the resulting hostname up again in the forward direction and checks whether the original IP comes back.

Test your own configuration

Send any email to hello@analyzemy.email and within seconds you get back a complete report covering every check described here.

Analyze your email now