Free Domain Validator: Check MX, SPF and DMARC Records
domainNS, MX, SPF, DMARCFree, 25 checks a day, no signup · Updated August 2, 2026
Nothing checked yet Paste a domain and the records come back in about two seconds.
- Domain syntaxPassDomain matches valid DNS naming rules.
- NS records (nameservers)Pass2 authoritative nameservers
- MX records (mail servers)Pass4 mail servers · primary: aspmx.l.google.com (priority 1)
- SPF (sender authentication)Passv=spf1 include:_spf.google.com include:spf.mtasv.net … ~all
- DMARC (anti-spoofing)Passv=DMARC1; p=reject; aspf=r; pct=100 … (policy: reject)
For a whole list, Cleanlist AI enriches every row of an uploaded CSV with a verified email, a phone number and the company behind the domain, across 25+ providers, at 1 credit per verified email. Get 14 days of Pro, free: 250 credits, 3 seats, agents, Sequences and Clu in Slack.
Start free trial Check a recipient address insteadTo validate a domain, check its live DNS records. Paste a domain above and Cleanlist AI queries its authoritative nameservers for NS records (is the domain managed), MX records (can it receive email), an SPF record at the root and a DMARC record at _dmarc.yourdomain.com. You get a verdict, a 0-100 score and the raw records in about two seconds, free for 25 domains a day with no signup.
Now enrich the whole list
Upload a CSV and Cleanlist AI returns a verified email, a phone number and the company behind each domain, looked up across 25+ providers, at 1 credit per verified email. The trial is 14 days of Pro, free: 250 credits, 3 seats, agents, Sequences and Clu in Slack. After it, Starter is $49 per seat a month, with 750 credits per seat.
98% verified work emails and 85% phone numbers on our 500-lead benchmark.
A demo of Clu, the Cleanlist AI agent, doing this for a whole list. Asked: Find the verified work email for everyone in Series B sales leaders Clu runs the tools, asks for confirmation before spending credits (Find work emails for 212 leads on Series B sales leaders, 212 credits), fills the list row by row and reports: 197 verified emails on the list, 15 not found. Want phone numbers for the 197 next?
10,000+ users, from founders to full sales teams
- Switched from
ZoomInfo - Case study
HackerOneSwitched from
Apollo- Switched from
Clay - Case study
Sumo LogicSwitched from
Clay- Switched from
Apollo - Case study
- Switched from
ZoomInfo - Switched from
ZoomInfo
How does Cleanlist AI validate a domain?
Cleanlist AI validates a domain with four live DNS lookups against its authoritative nameservers, and returns the raw records so you can read them yourself.
What this validator checks
Five live checks on any domain (for example example.com): domain syntax, NS records, MX records, SPF, and DMARC with its policy value surfaced. Cleanlist AI does not check DKIM, because the lookup needs a selector name chosen by whoever configured the mail service and it cannot be guessed from the domain. It also does not check domain blocklists, which need a paid reputation API.
Background reading: domain verification, email deliverability, and the free email verifier for the recipient side of the same problem.
- 01Live on this page
Domain syntax check
Cleanlist AI validates the input against DNS naming rules: label characters, label and total length limits, and a real top-level domain.
- 02Live on this page
NS lookup
Cleanlist AI resolves the domain's nameservers. A domain with no NS records is not actively delegated and will not resolve for anyone.
- 03Live on this page
MX lookup
Cleanlist AI queries the authoritative nameservers for mail exchange records and returns them sorted by priority, lowest first. No MX record means the domain cannot receive email at all.
- 04Live on this page
SPF and DMARC TXT lookup
Cleanlist AI fetches the TXT records at the domain root and at _dmarc.<domain>, then shows the raw SPF string and the DMARC policy value (p=none, p=quarantine or p=reject).
- Not checked
DKIM, WHOIS and blocklists
DKIM needs a selector name that cannot be guessed from the domain. WHOIS and registrar data need an external API, and blocklist reputation needs a paid one, so this page leaves all three out.
“Plenty of outbound campaigns fail at the DNS layer before a single email is sent. Google asks every sender for SPF or DKIM and a spam rate under 0.3%, and most teams have never looked at their own records. We built this validator so any GTM team can read them in two seconds, with no API and no signup.”
Who uses the free domain validator?
The people who run it most, and what each one runs it for.
- Sales teamsSpot a dead or risky prospect domain before a rep puts it in a sequence.
- MarketersConfirm sending domains have SPF and DMARC before a campaign goes live.
- DeliverabilityAudit DNS records that decide whether mail lands in the inbox or spam.
- FoundersCheck your own domain is authenticated before emailing partners or investors.
- RevOpsKeep prospect domain data accurate so routing and outreach hold up.
- AgenciesCheck client and prospect domains before they go into a live campaign.
Common questions about domain records
What DNS records does a domain need to send and receive email?
A domain needs four DNS records to send and receive email reliably: NS, MX, SPF and DMARC, with DKIM as the fifth. NS records prove the domain is actively managed and point at the nameservers that answer for it. MX records name the mail servers that accept incoming mail. An SPF record, a TXT record at the domain root starting with v=spf1, lists which servers are allowed to send as that domain. A DMARC record, a TXT record at _dmarc.yourdomain.com, tells receivers what to do when authentication fails. Cleanlist AI's free domain validator queries all four live, against the domain's authoritative nameservers, and returns the raw records alongside a 0-100 score.
What is an MX record?
An MX record is a DNS entry that names a mail server responsible for accepting email on behalf of a domain, together with a priority number where lower means preferred. A domain with no MX record cannot receive email at all, which makes a missing MX the most decisive signal a domain validator can return. Multiple MX records give a domain failover: if the priority 10 host is unreachable, the sending server tries the priority 20 host. Cleanlist AI's free domain validator returns the full set sorted by priority, so you can see whether a prospect runs Google Workspace, Microsoft 365, or a self-hosted server, which in turn tells you how likely that domain is to be configured as a catch-all.
What is an SPF record?
An SPF record is a TXT record published at a domain's root that lists the servers permitted to send email using that domain, and it always begins with v=spf1. A receiving server reads it, compares it to the IP the message arrived from, and decides whether the sender is authorised. The record ends with a policy: -all means reject anything not listed, ~all means treat it as suspicious, and +all effectively disables the check. Google's sender guidelines require every sender to set up SPF or DKIM for its sending domains, so a domain with neither is not meeting the published bar. Cleanlist AI's free domain validator returns the raw SPF string so you can read the policy for yourself.
What is DKIM?
DKIM is a cryptographic signature added to outgoing mail that lets a receiving server confirm the message really came from the domain it claims and was not altered in transit. The sending server signs each message with a private key; the receiver fetches the matching public key from a DNS TXT record at selector._domainkey.yourdomain.com and checks the signature. Yahoo's Sender Hub specifies a DKIM key length of 1024 bits or greater, and recommends 2048 bits. Cleanlist AI's free domain validator does not check DKIM, because the lookup needs the selector name, which is chosen by whoever configured the mail service and cannot be guessed from the domain alone.
What is DMARC?
DMARC is a TXT record at _dmarc.yourdomain.com that tells receiving servers what to do with mail claiming to be from that domain when SPF and DKIM fail, and where to send reports about it. The policy is set by the p= tag and has three values: p=none monitors and takes no action, p=quarantine sends failures to spam, and p=reject refuses them outright. Google requires senders of 5,000 or more messages a day to Gmail to publish a DMARC policy, and Yahoo urges every sending domain to publish one. Cleanlist AI's free domain validator fetches the record and surfaces the policy value, so you can tell a domain that is genuinely protected from one that merely has a record on file.
What does a failing DMARC record mean for cold email?
It means two different things depending on whose domain is failing. If your own sending domain has no DMARC record, or has p=none, you are below the bar Google publishes for senders of 5,000 or more messages a day to Gmail, and Yahoo urges a published policy for every sending domain. Expect throttling and spam placement as volume rises. If a prospect's domain has no DMARC, the risk is different: that domain is spoofable, replies you receive from it are harder to trust, and its mail infrastructure is likely unmanaged, which correlates with stale contact records. Cleanlist AI's free domain validator flags a missing DMARC as a warning rather than an error, because internal-only and parked domains legitimately do without one.
What are Google's and Yahoo's requirements for bulk senders?
Google requires all senders to set up SPF or DKIM authentication for their sending domains, transmit over TLS, publish valid forward and reverse DNS records, and keep the spam rate reported in Postmaster Tools below 0.3%, with a recommended target below 0.10%. Senders of 5,000 or more messages a day to Gmail accounts must additionally set up both SPF and DKIM, publish a DMARC policy, and support one-click unsubscribe on marketing mail. Yahoo requires one-click unsubscribe under RFC 8058 for promotional messages, enforced since June 2024, specifies a DKIM key of 1024 bits or greater with 2048 recommended, urges a published DMARC policy on every sending domain, and states that it will not specify a volume threshold for what counts as a bulk sender.
How does a domain's setup affect email deliverability?
A domain's DNS setup decides whether mail is authenticated before a receiving server ever looks at the content. SPF and DKIM establish that the message came from a server allowed to send as that domain; DMARC tells the receiver what to do when they fail and lets the domain owner see who is sending on its behalf. Without them a message arrives unauthenticated, which is the same posture a spoofer has, and filters treat it accordingly. Domain setup is only half the picture: Google measures spam complaint rate independently of authentication, so a fully authenticated domain sending to a stale list still gets throttled. Cleanlist AI's free email verifier handles the other half, checking whether the recipient address can receive mail at all.
Frequently asked questions
What it checks, how it differs from WHOIS, the daily limit and how far to trust it.
All free toolsWhat does the Cleanlist AI domain validator check?
Five live DNS checks: domain syntax, NS records (whether the domain has authoritative nameservers), MX records (which mail servers accept its email), SPF (a TXT record at the root starting with v=spf1) and DMARC (a TXT record at _dmarc.<domain>, with the policy value surfaced). Cleanlist AI does not check DKIM, because the lookup requires a selector name that cannot be guessed, and does not check domain blocklists, which need a paid reputation API.
Is this the same as a WHOIS lookup?
No. WHOIS returns registrar metadata and ownership history. Cleanlist AI's domain validator inspects the live DNS configuration that decides email deliverability. For B2B sales and marketing work the DNS picture is the one that changes your decision: a domain can have immaculate registrar records and still be unable to receive a single message.
Is there a usage limit?
Yes. Cleanlist AI allows 25 free domain checks per IP per day on this page, with no account. Past that, a new Cleanlist AI workspace starts with 14 days of Pro, free: 250 credits, 3 seats, agents, Sequences and Clu in Slack, so a whole list of domains runs in one pass. After the trial, the $0 Free plan is 50 credits a month, and Starter is $49 per seat a month.
How accurate is this tool?
DNS responses are deterministic: if the records exist on the authoritative nameservers, Cleanlist AI returns them. The interpretation is deliberately conservative. A missing SPF or DMARC is reported as a warning rather than an error, because internal-only, parked and no-mail domains legitimately publish neither.
Can this detect malicious or phishing domains?
Only as triage. A recently registered domain with no DMARC, no SPF and a single MX record on free hosting is a recognisable phishing shape, and Cleanlist AI surfaces each of those signals. It is not threat intelligence, and a definitive verdict needs a dedicated reputation service.
Sources
Every sender requirement quoted on this page comes from the mailbox provider that publishes it, read on August 2, 2026.
- 01
Google: Email sender guidelines. SPF or DKIM for every sender, TLS transmission, valid forward and reverse DNS, and a Postmaster Tools spam rate below 0.3% (recommended below 0.10%). Senders of 5,000 or more messages a day to Gmail must also publish a DMARC policy and support one-click unsubscribe.
- 02
Yahoo: Sender Hub FAQs. One-click unsubscribe under RFC 8058 for promotional mail, enforced since June 2024. DKIM keys of 1024 bits or greater, 2048 recommended. A published DMARC policy urged on every sending domain. Yahoo states it will not specify a bulk-sender volume threshold.
- 03
RFC 7208: Sender Policy Framework (SPF). The specification for the v=spf1 TXT record this tool reads.
- 04
RFC 6376: DomainKeys Identified Mail (DKIM). The signing scheme and the selector._domainkey record layout that makes DKIM un-guessable without the selector.
- 05
RFC 7489: DMARC. The policy framework behind the p=none, p=quarantine and p=reject values this tool surfaces.
Describe the job once. An agent runs it every week.
Clu turns one sentence into an agent. It searches 1B+ profiles, finds verified emails and phone numbers across 25+ providers, adds the people to your sequence and posts each run to Slack.
Weekly ICP outbound
Built by Clu from: “Every week, find 500 new people who match my ICP, get their emails and phones, and add them to Series B outbound.”
- Searched 1B+ profiles for new ICP matches500 foundPeople Search
- Ran the waterfall across 25+ providers487 emails · 412 phonesWaterfall
- Verified every email and phoneSMTP + catch-allVerification
- Added them to Series B outbound500 peopleSequences
- Posted the run to #pipelineSlackAgents
Friday 4:52 PM15 replies · 5 calls booked
Everything in the 14-day Pro trial
- Clu and agentsDescribe the job in one sentence. Clu builds the agent, runs it on a schedule or a CRM trigger and posts every run to Slack.
- People and Company SearchFind your buyers in 1B+ profiles from one sentence. Searching costs 0 credits.
- Waterfall enrichmentAsk 25+ providers in order and stop at the first verified email or phone number. 98% verified work emails and 85% phone numbers on a 500-lead benchmark.
- Email verificationRun SMTP and catch-all checks on every address before it reaches a sequence, at half a credit an email.
- ICP scoringScore every lead 0 to 100 against your ICP, with the reasons written down. The Research and Qualification skills do the digging.
- SequencesSend email from your reps' own inboxes, with LinkedIn steps and call tasks. A reply stops the sequence. Sending costs 0 credits.
- CRM syncTwo-way sync with HubSpot, Salesforce and Pipedrive. Push finished lists to Outreach, Salesloft and Lemlist.
- Chrome extensionGet a verified email and phone number in one click on LinkedIn, Sales Navigator, Salesforce and HubSpot.
- MCP and APIRun the same search and waterfall from Claude or ChatGPT with 36 MCP tools, or from your own code with the REST API.
14 days of Pro, free: 250 credits, 3 seats, agents, Sequences and Clu in Slack. Then Free at 50 credits a month, or Starter at $49 and Pro at $89 a seat a month.
Now enrich the whole list.
Upload the CSV or ask Clu. Every row comes back with a verified email, a phone number and the company behind the domain.
14 days of Pro, free.
