Enter a domain or an email address. The checker reads the domain's public DNS records and tells you, in plain language, what passes, what needs attention and how to fix it. Lookups run from your browser over DNS over HTTPS.
What the checker looks at
| Check | Record looked up | What passes |
|---|---|---|
| MX | MX at the domain | At least one MX record, and each MX host resolves to an IP address. A null MX (0 .) fails, because it says the domain takes no mail and replies would bounce. |
| SPF | TXT at the domain | Exactly one record starting v=spf1, valid syntax, 10 or fewer DNS lookups counting every nested include, and ending in ~all or -all. |
| DMARC | TXT at _dmarc | One record with p=quarantine or p=reject and a rua address for reports. p=none is a warning. For a subdomain, the parent domain's record is used if the subdomain has none. |
| DKIM | TXT at selector._domainkey | A key for at least one selector. RSA keys under 2048 bits get a warning. |
| Nameservers | NS at the domain | Two or more nameservers. |
| Website | A and AAAA at the domain and www | The domain points to a server, so a visitor sees a page or a redirect. |
| Tracking domain | CNAME at the host you enter | A CNAME record. Optional. |
| BIMI | TXT at default._bimi | Information only. BIMI has no effect on delivery. |
The checker only reads public DNS. It does not send email, test inbox placement or check blocklists.
Reading the results
- Pass: the record exists and follows current requirements.
- Warning: mail can still flow, but something weakens authentication or will break soon, such as
p=none, a 1024-bit DKIM key, or 9 or 10 SPF lookups. - Fail: a receiver will treat the domain as unauthenticated or unable to receive mail. Fix these before you send cold email from the domain.
- Info: context with no pass or fail, such as no DKIM key for the selectors tried, or an optional BIMI record.
Gmail and Yahoo require SPF, DKIM and DMARC for bulk senders, so a cold email domain needs all three to pass. Pair the results with the cold email calculator to plan how many domains and mailboxes you need.
Why DKIM depends on the selector
A DKIM public key is published at selector._domainkey.yourdomain.com, and the selector is a name your email provider picks. DNS has no way to list every selector on a domain, so no checker can prove DKIM is missing. This one tries the common selectors (google, selector1, selector2, default, k1, k2, s1, s2, dkim, mail) and any you add under Options. If none match, the result says "not found for these selectors", not "no DKIM".
To find your selector, open an email you sent from the domain, view its headers and look for s= in the DKIM-Signature header. Need a key? The DKIM record generator creates one in your browser.
Common fixes
- No SPF, or two SPF records: publish one TXT record that lists every service sending for the domain. Build it with the SPF record generator.
- Too many SPF lookups: remove includes for services you no longer use. Each provider's include can trigger several lookups of its own.
- No DMARC, or p=none: publish a record at
_dmarcwith a reporting address, then move to quarantine or reject once SPF and DKIM pass. The DMARC record generator writes it for you. - No MX: add the MX records from your mailbox provider, or replies to your cold emails have nowhere to go.
- No website: point the domain at a simple page or redirect it to your main site.
- Tracking domain: add the CNAME your sequencer gives you. On domains where Winnr hosts DNS you can add custom DNS records, including tracking CNAMEs.
For the full order of operations, see the cold email DNS setup checklist. If you'd rather not manage records at all, domains bought on Winnr get MX, SPF, DKIM and DMARC set up automatically, and the mailboxes on them are SMTP/IMAP accounts built for cold email.
Frequently asked questions
What does the domain health checker check?
It reads a domain's public DNS and checks MX records (and that each MX host resolves), SPF (exactly one record, valid syntax, an estimate of DNS lookups against the limit of 10, and how it ends), DMARC (present, policy, reporting address), DKIM keys for common selectors plus any you add, nameservers, A records for the domain and www, an optional custom tracking domain CNAME, and BIMI. It does not send email, test inbox placement or check blocklists.
Why does it say DKIM was not found for these selectors?
A DKIM key lives at a name like selector._domainkey.yourdomain.com, and the selector is chosen by whoever signs your mail. DNS has no way to list them, so the checker tries common ones (google, selector1, selector2, default, k1, k2, s1, s2, dkim, mail). If none match, your DKIM may still be fine under another name. Add your selector in the extra selectors box and check again.
How do I find my DKIM selector?
Open an email you sent from the domain, view the original message or headers, and find the DKIM-Signature header. The value after s= is the selector. Your provider's DKIM settings also show it. Google Workspace uses google by default, and Microsoft 365 uses selector1 and selector2.
What is the SPF 10 DNS lookup limit?
SPF evaluation may trigger at most 10 DNS lookups (RFC 7208). Each include, a, mx, ptr, exists and redirect counts, and so do the ones inside every include. Over 10, receivers return a permanent error and SPF fails. The checker follows your includes to estimate the total. If you are close to the limit, remove providers you no longer send from.
Should my DMARC policy be none, quarantine or reject?
Start with p=none and a rua address while you confirm SPF and DKIM pass for all your real mail, then move to p=quarantine or p=reject. p=none only monitors, so receivers get no instruction for mail that fails. Domains set up by Winnr use p=reject by default.
Does a cold email domain need a website?
Not for delivery, but prospects often type your domain into a browser before they reply. A domain that shows nothing looks less trustworthy. The usual fix is to redirect the sending domain to your main website, which Winnr can set up for you.
Do the lookups go through Winnr?
No. The DNS lookups run from your browser to Cloudflare's public DNS-over-HTTPS resolver, with Google Public DNS as a fallback. They do not go through Winnr's servers.
Why might the results differ from dig or another checker?
DNS answers are cached for the record's TTL, so a change you just made can take minutes to hours to show everywhere. Different resolvers can also be at different points in that window. If you just edited a record, wait and run the check again.
Does Winnr set these records up automatically?
Yes. For domains you buy on Winnr, or connect by pointing their nameservers at Winnr, Winnr creates the MX, SPF, DKIM and DMARC records for you. If you add records by hand instead, use this checker to confirm they are live.