What the DNS preflight checks
MX records tell other systems where the domain receives mail. SPF publishes which systems are permitted to send on the domain's behalf. DMARC tells receiving systems how to handle messages that fail alignment checks and where reports should go. DKIM publishes the public key used to verify a signature added by the sending provider.
The checker reads public DNS through DNS over HTTPS. It flags a missing MX record, no recognizable SPF policy, multiple SPF policies, no valid DMARC policy, or no DKIM public key at the selector you provide. A DMARC policy of p=none is shown as a warning because it monitors rather than requesting quarantine or rejection.
What a passing result means
It means the expected record types are visible in public DNS and pass a small set of structural checks. It does not validate every SPF include, cryptographically verify DKIM, inspect DMARC alignment across live messages or test mailbox configuration. It also says nothing about whether the offer, audience or copy belongs in an outbound motion.
DNS cannot predict inbox placement
Authentication is one layer in a sending system. Domain and mailbox reputation, sending patterns, provider rules, complaint behavior and message content can all change delivery. Treat this result as a launch gate, then monitor real bounce and response behavior. Use the outbound infrastructure calculator to plan capacity separately, compare managed options in Mailpool vs Inframail and Mailpool vs Maildoso, and read the multichannel outbound sequence guide before treating email volume as the whole motion.
From records to a safe motion
Want the whole outbound system reviewed?
In a free GTM Engine Review, we inspect the market, data, infrastructure and campaign logic together, then tell you which constraint matters first.
Book your GTM Engine Review