DNS Misconfiguration
Analyze DNS records (TXT, SPF) for security gaps.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
The security records nobody looks at until email breaks
Most of a domain’s security posture is written into DNS records that are set once and never reviewed. SPF says which servers may send mail as your domain; a missing or misconfigured SPF record is why your legitimate mail lands in spam and why anyone can spoof your address. This tool inspects the TXT and SPF records for a domain and points out the gaps, so you can see what your DNS is actually asserting.
What it checks for
It looks at whether an SPF record exists at all, whether it ends with a sensible policy rather than trailing off ambiguously, and whether the surrounding TXT records contain the things that ought to be there. A domain with no SPF, or an SPF that says "allow anything", is inviting spoofing; one with a hard fail policy and a tight list of senders is defending itself. Seeing the records side by side with an explanation turns opaque DNS syntax into a decision.
A read-only look, from your browser
The check reads published DNS, which is public information, and explains it; it changes nothing. Use it as a periodic review of a domain you manage, or to understand why mail from a domain behaves the way it does. Reviewing these records is one of the cheapest security improvements available, because the fix is a single DNS edit.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
- Port Exposure Explainer — Understand risks of specific open ports.
Frequently Asked Questions
What is an SPF record?
A DNS TXT record that lists which mail servers are allowed to send email for your domain. Without it, or with a permissive one, anyone can spoof your address and your legitimate mail is more likely to be marked as spam.
Why do TXT records matter for security?
They carry SPF and other policy statements that mail receivers use to decide whether a message is genuine. Missing or loose records weaken your defence against spoofing.
Does this change my DNS?
No. It only reads the published, public DNS records and explains them; any fix is a DNS edit you make yourself.
What is a good SPF policy?
One that lists exactly the servers that send your mail and ends with a fail directive so unlisted senders are rejected, rather than a permissive catch-all.
How often should I check?
Whenever you change mail providers, and periodically otherwise, since a stale SPF record that still lists an old provider is a common and easily missed gap.
Privacy & Security
Processed locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.
Firewall Rule Risk
NetworkEvaluate firewall rules for over-permissive exposure.