How SenderBeacon checks your domain
Last reviewed 2 October 2026.
What we look up
Every check is a read-only lookup of public data. We query public DNS resolvers (Cloudflare 1.1.1.1 and Google 8.8.8.8) with a 5-second timeout. We never send email to your domain and never ask for DNS or mailbox access.
- SPF: TXT records at the domain root starting with v=spf1. We flag missing or duplicate records, +all, a missing or neutral all, and we count DNS-querying mechanisms (include, a, mx, ptr, exists, redirect) through every nested include against the limit of 10 in RFC 7208.
- DMARC: the TXT record at _dmarc.domain. We flag missing or duplicate records, invalid or monitoring-only (p=none) policies, pct below 100, a missing rua report address, and sp=none under an enforced policy.
- DKIM: the TXT record at selector._domainkey.domain (CNAMEs are followed). DNS cannot list selectors, so if you have not given us yours we try these common ones: google, selector1, selector2, default, dkim, mail, k1, k2, k3, s1, s2, smtp, mx, fm1, fm2, fm3, protonmail, protonmail2, protonmail3, zmail, zoho, mandrill, mte1, sendgrid, mailgun, pic, krs, cm. We flag revoked keys (empty p=) and RSA keys under 1024 bits, and note 1024-bit keys. A key that is published does not prove your mail is being signed with it.
- MX: MX records, sorted by priority. We check that the first six mail hosts resolve to an IP address and recognise a null MX.
- HTTPS certificate: a TLS handshake to port 443 on the domain’s first A record. We report expiry, issuer and whether the certificate is trusted for the name. Private IP addresses are skipped.
How monitoring and alerts work
Monitored domains are checked twice a day, plus whenever you add a domain or click “Scan now”. A check must fail on two scans in a row before we send a failure alert, and we wait at least 48 hours before repeating one. When the text of an SPF, DKIM, DMARC or MX record changes, we send a change alert even if the new record is valid, because unexpected edits are how deliverability usually breaks. Certificate renewals do not trigger change alerts. When a failing check passes again, we send a recovery email.
What we cannot see
We do not see your actual mail. We cannot tell you whether a specific message reached the inbox, whether your sending IP is on a blocklist, or what your DMARC aggregate reports say. Correct DNS is necessary for good deliverability but not sufficient: content, sending volume and reputation matter too.
How this site is written
The checks above are deterministic code. Explanatory copy on this site is drafted with AI assistance and reviewed by a person before it is published, and provider-specific values are taken from each provider’s public documentation. If you spot something wrong, email hello@trysenderbeacon.com and we will correct it.