Enter a domain or an email address. The checker reads the domain's public DNS records and tells you, in plain language, what passes, what needs attention and how to fix it. Lookups run from your browser over DNS over HTTPS.

Options: DKIM selectors and tracking domain
Always checked: .
The open and click tracking host your sequencer uses. Checked for a CNAME.

What the checker looks at

CheckRecord looked upWhat passes
MXMX at the domainAt least one MX record, and each MX host resolves to an IP address. A null MX (0 .) fails, because it says the domain takes no mail and replies would bounce.
SPFTXT at the domainExactly one record starting v=spf1, valid syntax, 10 or fewer DNS lookups counting every nested include, and ending in ~all or -all.
DMARCTXT at _dmarcOne record with p=quarantine or p=reject and a rua address for reports. p=none is a warning. For a subdomain, the parent domain's record is used if the subdomain has none.
DKIMTXT at selector._domainkeyA key for at least one selector. RSA keys under 2048 bits get a warning.
NameserversNS at the domainTwo or more nameservers.
WebsiteA and AAAA at the domain and wwwThe domain points to a server, so a visitor sees a page or a redirect.
Tracking domainCNAME at the host you enterA CNAME record. Optional.
BIMITXT at default._bimiInformation only. BIMI has no effect on delivery.

The checker only reads public DNS. It does not send email, test inbox placement or check blocklists.

Reading the results

Gmail and Yahoo require SPF, DKIM and DMARC for bulk senders, so a cold email domain needs all three to pass. Pair the results with the cold email calculator to plan how many domains and mailboxes you need.

Why DKIM depends on the selector

A DKIM public key is published at selector._domainkey.yourdomain.com, and the selector is a name your email provider picks. DNS has no way to list every selector on a domain, so no checker can prove DKIM is missing. This one tries the common selectors (google, selector1, selector2, default, k1, k2, s1, s2, dkim, mail) and any you add under Options. If none match, the result says "not found for these selectors", not "no DKIM".

To find your selector, open an email you sent from the domain, view its headers and look for s= in the DKIM-Signature header. Need a key? The DKIM record generator creates one in your browser.

Common fixes

For the full order of operations, see the cold email DNS setup checklist. If you'd rather not manage records at all, domains bought on Winnr get MX, SPF, DKIM and DMARC set up automatically, and the mailboxes on them are SMTP/IMAP accounts built for cold email.

Frequently asked questions

What does the domain health checker check?

It reads a domain's public DNS and checks MX records (and that each MX host resolves), SPF (exactly one record, valid syntax, an estimate of DNS lookups against the limit of 10, and how it ends), DMARC (present, policy, reporting address), DKIM keys for common selectors plus any you add, nameservers, A records for the domain and www, an optional custom tracking domain CNAME, and BIMI. It does not send email, test inbox placement or check blocklists.

Why does it say DKIM was not found for these selectors?

A DKIM key lives at a name like selector._domainkey.yourdomain.com, and the selector is chosen by whoever signs your mail. DNS has no way to list them, so the checker tries common ones (google, selector1, selector2, default, k1, k2, s1, s2, dkim, mail). If none match, your DKIM may still be fine under another name. Add your selector in the extra selectors box and check again.

How do I find my DKIM selector?

Open an email you sent from the domain, view the original message or headers, and find the DKIM-Signature header. The value after s= is the selector. Your provider's DKIM settings also show it. Google Workspace uses google by default, and Microsoft 365 uses selector1 and selector2.

What is the SPF 10 DNS lookup limit?

SPF evaluation may trigger at most 10 DNS lookups (RFC 7208). Each include, a, mx, ptr, exists and redirect counts, and so do the ones inside every include. Over 10, receivers return a permanent error and SPF fails. The checker follows your includes to estimate the total. If you are close to the limit, remove providers you no longer send from.

Should my DMARC policy be none, quarantine or reject?

Start with p=none and a rua address while you confirm SPF and DKIM pass for all your real mail, then move to p=quarantine or p=reject. p=none only monitors, so receivers get no instruction for mail that fails. Domains set up by Winnr use p=reject by default.

Does a cold email domain need a website?

Not for delivery, but prospects often type your domain into a browser before they reply. A domain that shows nothing looks less trustworthy. The usual fix is to redirect the sending domain to your main website, which Winnr can set up for you.

Do the lookups go through Winnr?

No. The DNS lookups run from your browser to Cloudflare's public DNS-over-HTTPS resolver, with Google Public DNS as a fallback. They do not go through Winnr's servers.

Why might the results differ from dig or another checker?

DNS answers are cached for the record's TTL, so a change you just made can take minutes to hours to show everywhere. Different resolvers can also be at different points in that window. If you just edited a record, wait and run the check again.

Does Winnr set these records up automatically?

Yes. For domains you buy on Winnr, or connect by pointing their nameservers at Winnr, Winnr creates the MX, SPF, DKIM and DMARC records for you. If you add records by hand instead, use this checker to confirm they are live.