A Python module, command line utility, and web application for validating SPF and DMARC DNS records.
This project is maintained by one developer. Please consider sponsoring my work if you or your organization benefit from it.
- API, CLI, and web interfaces
- Can test multiple domains at once
- CLI output in JSON or CSV format
- DNSSEC validation
- SPF
- Record validation
- Counting of DNS lookups and void lookups
- Counting of lookups per mechanism
- DMARC
- Validation and parsing of DMARC records
- Shows warnings when the DMARC record is made ineffective by
spvalues, or by use of thepct/rf/ritags that were removed in RFC 9989 - Checks for authorization records on reporting email addresses
- BIMI
- Validation of the mark format and certificate against the Minimum Security Requirements for Issuance of Mark Certificates
- Parsing of the mark certificate
- MX records
- Preference
- IPv4 and IPv6 addresses
- Optional STARTTLS and TLS testing (pass
--check-mx-tls) - Use of DNSSEC/TLSA/DANE to pin certificates
- MTA-STS
- SMTP TLS reporting
- Record and policy parsing and validation
- SOA record parsing
- Nameserver listing
- Build the image using
docker build . -t checkdmarc - Use the image with a command like
docker run --rm checkdmarc google.nl