Skip to content

How SenderBeacon checks your domain

Last reviewed 2 October 2026.

What we look up

Every check is a read-only lookup of public data. We query public DNS resolvers (Cloudflare 1.1.1.1 and Google 8.8.8.8) with a 5-second timeout. We never send email to your domain and never ask for DNS or mailbox access.

How monitoring and alerts work

Monitored domains are checked twice a day, plus whenever you add a domain or click “Scan now”. A check must fail on two scans in a row before we send a failure alert, and we wait at least 48 hours before repeating one. When the text of an SPF, DKIM, DMARC or MX record changes, we send a change alert even if the new record is valid, because unexpected edits are how deliverability usually breaks. Certificate renewals do not trigger change alerts. When a failing check passes again, we send a recovery email.

What we cannot see

We do not see your actual mail. We cannot tell you whether a specific message reached the inbox, whether your sending IP is on a blocklist, or what your DMARC aggregate reports say. Correct DNS is necessary for good deliverability but not sufficient: content, sending volume and reputation matter too.

How this site is written

The checks above are deterministic code. Explanatory copy on this site is drafted with AI assistance and reviewed by a person before it is published, and provider-specific values are taken from each provider’s public documentation. If you spot something wrong, email hello@trysenderbeacon.com and we will correct it.

Run a free check