Email Deliverability & Inbound Health Diagnostic Studio
Setting up custom domain email addresses (such as contact@yourcompany.com) requires configuring several Domain Name System (DNS) records. If any of these records are missing, misconfigured, or pointing to defunct mail servers, your business will suffer: inbound emails from clients will bounce back as undeliverable, and your outbound messages will be flagged as spam or outright rejected by major inbox providers like Google Workspace, Yahoo Mail, and Microsoft 365.
The DwellixTools Email Deliverability & Inbound Tester Studio conducts a comprehensive DNS health audit for any domain name. By querying secure DNS-over-HTTPS (DoH) endpoints directly from your browser, the tool verifies your Mail Exchange (MX) routing, inspects Sender Policy Framework (SPF) authorizations, and analyzes DMARC authentication policies to ensure your domain is configured for maximum inbox deliverability.
Key Diagnostic Checks & Health Audits
- Mail Exchange (MX) Record Resolution: Scans your domain for published MX server entries and orders them by numerical priority. Verifies that at least one active mail exchanger is configured to accept incoming SMTP connections.
- Sender Policy Framework (SPF) Validation: Locates and parses your domain’s
v=spf1TXT record. Confirms whether your email delivery vendors (such as Google Workspace, Microsoft 365, SendGrid, Mailchimp, or Amazon SES) are explicitly authorized to send mail on your behalf. - DMARC Security Policy Inspection: Queries the
_dmarc.{domain}subdomain to verify whether your domain has an active DMARC policy (p=none,p=quarantine, orp=reject), protecting your domain reputation against phishing and executive spoofing. - Visual Status Scorecard: Categorizes domain readiness using immediate visual health indicators:
- Pass (Green): Mail routing and authentication records are properly configured.
- Warning (Orange): Inbound mail works, but missing or weak DMARC/SPF records leave outbound messages vulnerable to spam filters.
- Danger (Red): Missing or invalid MX records; inbound emails are actively bouncing.
- 1-Click Plain-Text Technical Report: Generates a clean diagnostic summary of all retrieved DNS records and recommended fixes, formatted for easy sharing with your web hosting provider or IT department.
- Client-Side DNS Queries: All lookups are executed directly from your browser to authoritative DNS-over-HTTPS endpoints. DwellixTools does not store, log, or track your domain names or email addresses on its servers.
The Big Three Email Authentication Protocols
Modern email deliverability relies on three interconnected security standards designed to authenticate sender identity and eliminate spam:
| Security Protocol | DNS Record Type | Primary Purpose | Consequence If Missing |
|---|---|---|---|
| MX (Mail Exchange) | MX |
Directs incoming emails to your mail server | Complete failure to receive emails; all incoming mail bounces |
| SPF (Sender Policy Framework) | TXT (v=spf1 ...) |
Lists IP addresses authorized to send emails | Outbound emails marked as suspicious or sent to Spam folder |
| DKIM (DomainKeys Identified Mail) | TXT (selector._domainkey) |
Cryptographically signs messages to prove integrity | Messages cannot be verified against tampering in transit |
| DMARC (Domain-based Auth) | TXT (_dmarc.domain) |
Instructs inboxes how to treat failed SPF/DKIM mail | Hackers can easily spoof your email address to scam clients |
Mandatory Requirements for Google & Yahoo (2024+ Sender Mandates)
Starting in 2024, Google and Yahoo implemented strict, mandatory deliverability enforcement for all domain owners, with heightened requirements for organizations sending bulk email (exceeding 5,000 messages per day):
- Mandatory SPF & DKIM: Every outbound email must pass either SPF or DKIM authentication.
- Mandatory DMARC Policy: The sending domain must publish a valid DMARC record. Even an initial monitoring policy (
p=none) fulfills the baseline requirement. - Valid Forward and Reverse DNS (PTR): Sending server IP addresses must match valid reverse DNS records.
- Spam Rate Below 0.3%: Senders must keep user-reported spam rates strictly under 0.10% (and never exceed a 0.30% threshold in Google Postmaster Tools) to prevent domain-wide throttling or blacklisting.
- One-Click Unsubscribe: Marketing and promotional emails must support RFC 8058 one-click unsubscribe headers.
Step-by-Step Deliverability Troubleshooting Guide
1. Step 1: Run the Domain Audit
Type your domain name (e.g., yourbrand.com) into the input field above and click Check Deliverability.
2. Step 2: Resolve Red (Danger) Inbound Issues
If the test reports missing MX records:
- Log in to your domain registrar or DNS host (Cloudflare, GoDaddy, Namecheap, Google Domains).
- Add the MX records provided by your email provider. For Google Workspace, enter
10 smtp.google.com(or the legacy ASPMX records). For Microsoft 365, enteryourbrand-com.mail.protection.outlook.com.
3. Step 3: Configure SPF Record
Ensure you have exactly one SPF TXT record on your root domain. Multiple SPF records cause permanent PermError validation failures:
- Example for Google Workspace:
v=spf1 include:_spf.google.com ~all - Example combining Google and SendGrid:
v=spf1 include:_spf.google.com include:sendgrid.net ~all
4. Step 4: Publish a DMARC Record
Add a TXT record with host name _dmarc and value:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbrand.com
Once you verify that legitimate emails are delivering smoothly, elevate the policy from p=none to p=quarantine and ultimately p=reject.
Frequently Asked Questions (FAQ)
Why do my emails go to the spam folder even though my MX records are working?
MX records only govern inbound mail (receiving messages). Whether your outbound emails land in the primary inbox or the spam folder is determined by sender authentication (SPF, DKIM, DMARC), domain reputation, content triggers, and IP history. If your domain lacks SPF and DMARC records, inbox providers like Gmail and Outlook will treat your messages with suspicion.
What is the difference between a soft fail (~all) and a hard fail (-all) in SPF?
The suffix at the end of an SPF record tells receiving mail servers what to do with messages sent from unauthorized IP addresses:
~all(SoftFail): Unauthorized emails are accepted but flagged as suspicious, often routing to the spam folder. Recommended while testing new email services.-all(HardFail): Unauthorized emails are strictly rejected at the gateway. Provides maximum protection against spoofing once all legitimate email sources are accounted for.
What does p=none, p=quarantine, and p=reject mean in DMARC?
The p= tag defines your domain’s enforcement policy:
p=none: Monitoring mode. Inboxes deliver messages normally and send diagnostic reports to yourruaemail address.p=quarantine: Inboxes deliver failed messages directly to the recipient’s Spam or Junk folder.p=reject: Inboxes immediately block and discard failed messages, preventing spoofed emails from ever reaching the recipient.
What is the SPF 10-DNS-lookup limit?
RFC 7208 specifies that an SPF evaluation must not require more than 10 nested DNS lookups (triggered by mechanisms like include:, a, mx, and redirect). If your SPF record exceeds 10 lookups, receiving servers will return an SPF PermError, causing authentication to fail. If you use multiple third-party marketing services, you may need to flatten your SPF record.
How long does it take for DNS changes to take effect?
DNS record updates typically propagate across global networks within 15 minutes to 2 hours. However, propagation can take up to 24 to 48 hours depending on your previous record’s Time-To-Live (TTL) setting.
Does this tool send test emails or check blacklists?
This tool performs real-time DNS diagnostic inspections of your domain’s email architecture. It queries authoritative name servers via DNS-over-HTTPS to verify MX, SPF, and DMARC configurations without sending test emails or exposing your inbox to spam.
Are my checked domains or email addresses stored on your servers?
No. All DNS queries are executed directly from your browser to public DNS-over-HTTPS endpoints. DwellixTools does not record, log, or track your domain names, email addresses, or diagnostic results on any server.