Skip to content
HostOn

Tools

DNS check

Shows a domain’s key DNS records and evaluates SPF and DMARC.

What the DNS check shows

The DNS check queries a domain’s public DNS records and evaluates the ones that matter for email delivery. Within seconds you can see whether your website and mailboxes are set up correctly.

  • A and AAAA: the IPv4 and IPv6 address where your website can be reached.
  • MX: the mail servers that accept emails for your domain. The number in front is the priority; the lowest value is tried first.
  • Name servers: who manages your domain’s DNS zone. You always change records with this provider.
  • SPF and DMARC: whether recipients can verify that emails using your sender address really come from you.
  • CAA: which certificate authorities may issue SSL certificates for your domain. Without a CAA record there is no restriction.

How to read SPF and DMARC

An SPF record starts with v=spf1 and usually ends with ~all or -all. With -all you ask recipients to reject emails from servers that are not listed; ~all only marks them as suspicious. Exactly one SPF record is allowed per domain. Also keep an eye on the limit of ten DNS lookups: every include in the record counts towards it, and if it is exceeded, the SPF check fails.

DMARC is published at _dmarc.your-company.ch. The policy p=none is for monitoring: with a report address (rua) you receive reports, but recipients handle your emails as before. With p=quarantine, emails that pass neither SPF nor DKIM in alignment with the sender domain go to the spam folder; with p=reject they are rejected. Only move to quarantine or reject once the reports show that all legitimate senders are set up correctly.

Tip: If your emails are rejected even though the records are correct, also check whether your mail server’s IP address is on a blacklist.

Email hosting at HostOn

With email hosting at HostOn from CHF 2.90 per month, we show you the right MX, SPF and DKIM records in the client area after you order. You copy the values to your DNS provider and then confirm the result with the DNS check.

Frequently asked questions

MX defines which server accepts emails for your domain. SPF lists the servers allowed to send on your behalf. DKIM signs outgoing emails with a key whose public part is published in DNS. DMARC tells recipients what to do with emails that pass neither SPF nor DKIM in alignment with your sender domain.

It depends on the record’s TTL. Resolvers cache the old value for as long as the TTL specifies, often between one hour and one day. A name server change can take up to 48 hours. If the DNS check still shows old values, wait for the TTL to expire and check again.

A DKIM key is published under a name such as selector._domainkey.your-company.ch. The selector is chosen by your email provider and cannot be derived from the domain. Without it, no tool can look up the key directly. You will find it in the header of a sent email (DKIM-Signature field, value s=) or from your email provider.

If a domain has more than one TXT record starting with v=spf1, the SPF check aborts with an error. Many recipients treat that like a missing SPF record. Put all permitted senders, for example your mail server and a newsletter service, into a single record.

Questions? Write to us in your language.

We reply in the language you write in – German, French, Italian, English and two more.

DEENFRITESRO

Usually answered on the same working day

Workstations with headsets and laptops in a bright office
  • Ticketrecommended

    For anything about your account: hosting, domains, invoices. With history and attachments.

    Open a ticket
  • Email

    For questions before you order and for quotes.

    support@hoston.ch

    Send an email
  • WhatsApp

    For short questions. Please don't send passwords or customer data.

    Send a message

Check first: is there an ongoing incident?

status.hoston.ch

Contact · Migration service · Tools