Check email authentication in this order: SPF, then DKIM, then DMARC, then optional BIMI and MX. Bookmark the clean Arawa Mail URLs with no tracking parameters: SPF checker, DKIM checker, DMARC checker. A missing DMARC record is not the same as p=none. Passing one public checker does not mean Enable Sending is done.
Operators often see a domain that “looks fine” in one email authentication checker and fails in another. The usual cause is sequence, not superstition: someone ran a BIMI or DMARC policy checker before SPF and the DKIM selector were published, or compared two vendors on one From address.
Bookmark these URLs (no UTM)
- https://app.arawamail.com/tools/spf-checker
- https://app.arawamail.com/tools/dkim-checker
- https://app.arawamail.com/tools/dmarc-checker
- https://app.arawamail.com/tools/bimi-checker
- https://app.arawamail.com/tools/mx-lookup
- Directory: arawamail.com/tools
Do not paste utm_ query strings onto these links. Tools do not require an account.
How we analyzed this
Live tool paths were confirmed on 26 September 2026 on the Arawa Mail tools surface. Protocol definitions stay on the published explainer SPF, DKIM, and DMARC explained. This hub only sequences checks and points to first-party URLs. Third-party checkers (MXToolbox, dmarcian, Google Admin Toolbox) remain valid alternatives; they are not the default path here.
Step 1 — SPF checker
Find the actual envelope sender domain in Return-Path or Authentication-Results, then paste that MAIL FROM domain into the SPF checker. The tool inspects the published SPF TXT record, authorized senders, policy, and the 10-lookup limit.
Good looks like one published policy that names every vendor allowed to send for that domain, without a lookup explosion. If the record is missing, flattened badly, or over the lookup cap, stop and read SPF 10 DNS lookup limit before you add another include:.
Step 2 — DKIM checker
Paste the sending domain and the selector into the DKIM checker. The tool locates the selector’s DNS record and checks that a public key is published.
If DKIM fails, separate two problems: the selector is not published at all, versus a sending vendor is signing with a different domain than the From address. Selector rotation belongs on DKIM key rotation. Two vendors on one From belong on two vendors, one From address.
Step 3 — DMARC policy and alignment
Start with the exact domain in the visible From header; check its _dmarc record and applicable organizational-domain fallback using the DMARC checker. It inspects policy, enforcement, coverage, and reporting.
Missing record: no _dmarc TXT. That is not a policy. Receivers have nothing to enforce.
p=none: a published monitor-only policy. Useful while you collect reports. Not enforcement.
SPF can “pass” while DMARC still fails if the authenticated domain does not align with the From domain. That gap is covered in DMARC alignment vs SPF pass. After you have aggregate XML, use how to read a DMARC report.
Volume senders still need SPF + DKIM + DMARC as table stakes under Gmail and Yahoo bulk-sender requirements (2026).
Step 4 — Optional BIMI and MX
Do not check BIMI before DMARC. BIMI needs a strong published DMARC policy and is optional for transactional mail. Use the BIMI checker only after DMARC enforcement is real, then read BIMI explained.
Use MX lookup when the question is inbound routing, not outbound authentication. Primer: MX records explained. Product DNS reference: how ArawaMail sets up DNS.
Checklist after the four checks
- SPF published for the MAIL FROM domain, within the lookup limit. SPF alignment with the visible From is a separate DMARC check.
- DKIM selector published and used by the actual sending vendor.
- DMARC present; know whether it is missing,
p=none, or enforcing. - Alignment checked if two vendors share one From.
- BIMI only if you already enforce DMARC and want a brand mark.
- Failed checks go to domain onboarding and Enable Sending in the app — a green checker is not that step.
FAQ
Which record do I check first?
SPF, then DKIM, then DMARC. BIMI last.
What does a missing DMARC record look like versus p=none?
Missing means no policy exists. p=none means a published monitor policy.
If DKIM fails, is that a selector problem or a vendor problem?
Run the DKIM checker with the selector your vendor documents. A published key does not prove a signature passes. Inspect Authentication-Results on a test message. DKIM pass with DMARC failure means the passing signature may be unaligned, not that the key itself is wrong.
Should I check BIMI before DMARC?
No.
Which URL should I bookmark?
The app.arawamail.com/tools/… paths above, with no UTM parameters.
Sources and review
Documentation reviewed on 3 October 2026. Examples are illustrative and must be adapted to your application.