Skip to content

Free Domain Validator: Check MX, SPF and DMARC Records

domainNS, MX, SPF, DMARCFree, 25 checks a day, no signup · Updated August 2, 2026

Domain validatorLive lookup25 / dayFree, no signup

25 of 25 free checks remaining today

Nothing checked yet Paste a domain and the records come back in about two seconds.

ExampleValidlinear.appdeliverability score
  • Domain syntaxPassDomain matches valid DNS naming rules.
  • NS records (nameservers)Pass2 authoritative nameservers
  • MX records (mail servers)Pass4 mail servers · primary: aspmx.l.google.com (priority 1)
  • SPF (sender authentication)Passv=spf1 include:_spf.google.com include:spf.mtasv.net … ~all
  • DMARC (anti-spoofing)Passv=DMARC1; p=reject; aspf=r; pct=100 … (policy: reject)

For a whole list, Cleanlist AI enriches every row of an uploaded CSV with a verified email, a phone number and the company behind the domain, across 25+ providers, at 1 credit per verified email. Get 14 days of Pro, free: 250 credits, 3 seats, agents, Sequences and Clu in Slack.

Start free trial Check a recipient address instead
Try

To validate a domain, check its live DNS records. Paste a domain above and Cleanlist AI queries its authoritative nameservers for NS records (is the domain managed), MX records (can it receive email), an SPF record at the root and a DMARC record at _dmarc.yourdomain.com. You get a verdict, a 0-100 score and the raw records in about two seconds, free for 25 domains a day with no signup.

Now enrich the whole list

Upload a CSV and Cleanlist AI returns a verified email, a phone number and the company behind each domain, looked up across 25+ providers, at 1 credit per verified email. The trial is 14 days of Pro, free: 250 credits, 3 seats, agents, Sequences and Clu in Slack. After it, Starter is $49 per seat a month, with 750 credits per seat.

98% verified work emails and 85% phone numbers on our 500-lead benchmark.

A demo of Clu, the Cleanlist AI agent, doing this for a whole list. Asked: Find the verified work email for everyone in Series B sales leaders Clu runs the tools, asks for confirmation before spending credits (Find work emails for 212 leads on Series B sales leaders, 212 credits), fills the list row by row and reports: 197 verified emails on the list, 15 not found. Want phone numbers for the 197 next?

See the 25+ provider waterfall

10,000+ users, from founders to full sales teams

  • Switched fromZoomInfo
  • Case study
  • HackerOneSwitched fromApollo
  • Switched fromClay
  • Case study
  • Sumo LogicSwitched fromClay
  • Switched fromApollo
  • Case study
  • Switched fromZoomInfo
  • Switched fromZoomInfo

How does Cleanlist AI validate a domain?

Cleanlist AI validates a domain with four live DNS lookups against its authoritative nameservers, and returns the raw records so you can read them yourself.

What this validator checks

Five live checks on any domain (for example example.com): domain syntax, NS records, MX records, SPF, and DMARC with its policy value surfaced. Cleanlist AI does not check DKIM, because the lookup needs a selector name chosen by whoever configured the mail service and it cannot be guessed from the domain. It also does not check domain blocklists, which need a paid reputation API.

Background reading: domain verification, email deliverability, and the free email verifier for the recipient side of the same problem.

  1. 01Live on this page

    Domain syntax check

    Cleanlist AI validates the input against DNS naming rules: label characters, label and total length limits, and a real top-level domain.

  2. 02Live on this page

    NS lookup

    Cleanlist AI resolves the domain's nameservers. A domain with no NS records is not actively delegated and will not resolve for anyone.

  3. 03Live on this page

    MX lookup

    Cleanlist AI queries the authoritative nameservers for mail exchange records and returns them sorted by priority, lowest first. No MX record means the domain cannot receive email at all.

  4. 04Live on this page

    SPF and DMARC TXT lookup

    Cleanlist AI fetches the TXT records at the domain root and at _dmarc.<domain>, then shows the raw SPF string and the DMARC policy value (p=none, p=quarantine or p=reject).

  5. Not checked

    DKIM, WHOIS and blocklists

    DKIM needs a selector name that cannot be guessed from the domain. WHOIS and registrar data need an external API, and blocklist reputation needs a paid one, so this page leaves all three out.

“Plenty of outbound campaigns fail at the DNS layer before a single email is sent. Google asks every sender for SPF or DKIM and a spam rate under 0.3%, and most teams have never looked at their own records. We built this validator so any GTM team can read them in two seconds, with no API and no signup.”

Victor Paraschiv
Co-Founder, Cleanlist AI

Who uses the free domain validator?

The people who run it most, and what each one runs it for.

  • Sales teamsSpot a dead or risky prospect domain before a rep puts it in a sequence.
  • MarketersConfirm sending domains have SPF and DMARC before a campaign goes live.
  • DeliverabilityAudit DNS records that decide whether mail lands in the inbox or spam.
  • FoundersCheck your own domain is authenticated before emailing partners or investors.
  • RevOpsKeep prospect domain data accurate so routing and outreach hold up.
  • AgenciesCheck client and prospect domains before they go into a live campaign.

Common questions about domain records

What DNS records does a domain need to send and receive email?

A domain needs four DNS records to send and receive email reliably: NS, MX, SPF and DMARC, with DKIM as the fifth. NS records prove the domain is actively managed and point at the nameservers that answer for it. MX records name the mail servers that accept incoming mail. An SPF record, a TXT record at the domain root starting with v=spf1, lists which servers are allowed to send as that domain. A DMARC record, a TXT record at _dmarc.yourdomain.com, tells receivers what to do when authentication fails. Cleanlist AI's free domain validator queries all four live, against the domain's authoritative nameservers, and returns the raw records alongside a 0-100 score.

What is an MX record?

An MX record is a DNS entry that names a mail server responsible for accepting email on behalf of a domain, together with a priority number where lower means preferred. A domain with no MX record cannot receive email at all, which makes a missing MX the most decisive signal a domain validator can return. Multiple MX records give a domain failover: if the priority 10 host is unreachable, the sending server tries the priority 20 host. Cleanlist AI's free domain validator returns the full set sorted by priority, so you can see whether a prospect runs Google Workspace, Microsoft 365, or a self-hosted server, which in turn tells you how likely that domain is to be configured as a catch-all.

What is an SPF record?

An SPF record is a TXT record published at a domain's root that lists the servers permitted to send email using that domain, and it always begins with v=spf1. A receiving server reads it, compares it to the IP the message arrived from, and decides whether the sender is authorised. The record ends with a policy: -all means reject anything not listed, ~all means treat it as suspicious, and +all effectively disables the check. Google's sender guidelines require every sender to set up SPF or DKIM for its sending domains, so a domain with neither is not meeting the published bar. Cleanlist AI's free domain validator returns the raw SPF string so you can read the policy for yourself.

What is DKIM?

DKIM is a cryptographic signature added to outgoing mail that lets a receiving server confirm the message really came from the domain it claims and was not altered in transit. The sending server signs each message with a private key; the receiver fetches the matching public key from a DNS TXT record at selector._domainkey.yourdomain.com and checks the signature. Yahoo's Sender Hub specifies a DKIM key length of 1024 bits or greater, and recommends 2048 bits. Cleanlist AI's free domain validator does not check DKIM, because the lookup needs the selector name, which is chosen by whoever configured the mail service and cannot be guessed from the domain alone.

What is DMARC?

DMARC is a TXT record at _dmarc.yourdomain.com that tells receiving servers what to do with mail claiming to be from that domain when SPF and DKIM fail, and where to send reports about it. The policy is set by the p= tag and has three values: p=none monitors and takes no action, p=quarantine sends failures to spam, and p=reject refuses them outright. Google requires senders of 5,000 or more messages a day to Gmail to publish a DMARC policy, and Yahoo urges every sending domain to publish one. Cleanlist AI's free domain validator fetches the record and surfaces the policy value, so you can tell a domain that is genuinely protected from one that merely has a record on file.

What does a failing DMARC record mean for cold email?

It means two different things depending on whose domain is failing. If your own sending domain has no DMARC record, or has p=none, you are below the bar Google publishes for senders of 5,000 or more messages a day to Gmail, and Yahoo urges a published policy for every sending domain. Expect throttling and spam placement as volume rises. If a prospect's domain has no DMARC, the risk is different: that domain is spoofable, replies you receive from it are harder to trust, and its mail infrastructure is likely unmanaged, which correlates with stale contact records. Cleanlist AI's free domain validator flags a missing DMARC as a warning rather than an error, because internal-only and parked domains legitimately do without one.

What are Google's and Yahoo's requirements for bulk senders?

Google requires all senders to set up SPF or DKIM authentication for their sending domains, transmit over TLS, publish valid forward and reverse DNS records, and keep the spam rate reported in Postmaster Tools below 0.3%, with a recommended target below 0.10%. Senders of 5,000 or more messages a day to Gmail accounts must additionally set up both SPF and DKIM, publish a DMARC policy, and support one-click unsubscribe on marketing mail. Yahoo requires one-click unsubscribe under RFC 8058 for promotional messages, enforced since June 2024, specifies a DKIM key of 1024 bits or greater with 2048 recommended, urges a published DMARC policy on every sending domain, and states that it will not specify a volume threshold for what counts as a bulk sender.

How does a domain's setup affect email deliverability?

A domain's DNS setup decides whether mail is authenticated before a receiving server ever looks at the content. SPF and DKIM establish that the message came from a server allowed to send as that domain; DMARC tells the receiver what to do when they fail and lets the domain owner see who is sending on its behalf. Without them a message arrives unauthenticated, which is the same posture a spoofer has, and filters treat it accordingly. Domain setup is only half the picture: Google measures spam complaint rate independently of authentication, so a fully authenticated domain sending to a stale list still gets throttled. Cleanlist AI's free email verifier handles the other half, checking whether the recipient address can receive mail at all.

Frequently asked questions

What it checks, how it differs from WHOIS, the daily limit and how far to trust it.

All free tools
What does the Cleanlist AI domain validator check?

Five live DNS checks: domain syntax, NS records (whether the domain has authoritative nameservers), MX records (which mail servers accept its email), SPF (a TXT record at the root starting with v=spf1) and DMARC (a TXT record at _dmarc.<domain>, with the policy value surfaced). Cleanlist AI does not check DKIM, because the lookup requires a selector name that cannot be guessed, and does not check domain blocklists, which need a paid reputation API.

Is this the same as a WHOIS lookup?

No. WHOIS returns registrar metadata and ownership history. Cleanlist AI's domain validator inspects the live DNS configuration that decides email deliverability. For B2B sales and marketing work the DNS picture is the one that changes your decision: a domain can have immaculate registrar records and still be unable to receive a single message.

Is there a usage limit?

Yes. Cleanlist AI allows 25 free domain checks per IP per day on this page, with no account. Past that, a new Cleanlist AI workspace starts with 14 days of Pro, free: 250 credits, 3 seats, agents, Sequences and Clu in Slack, so a whole list of domains runs in one pass. After the trial, the $0 Free plan is 50 credits a month, and Starter is $49 per seat a month.

How accurate is this tool?

DNS responses are deterministic: if the records exist on the authoritative nameservers, Cleanlist AI returns them. The interpretation is deliberately conservative. A missing SPF or DMARC is reported as a warning rather than an error, because internal-only, parked and no-mail domains legitimately publish neither.

Can this detect malicious or phishing domains?

Only as triage. A recently registered domain with no DMARC, no SPF and a single MX record on free hosting is a recognisable phishing shape, and Cleanlist AI surfaces each of those signals. It is not threat intelligence, and a definitive verdict needs a dedicated reputation service.

Sources

Every sender requirement quoted on this page comes from the mailbox provider that publishes it, read on August 2, 2026.

  1. 01

    Google: Email sender guidelines. SPF or DKIM for every sender, TLS transmission, valid forward and reverse DNS, and a Postmaster Tools spam rate below 0.3% (recommended below 0.10%). Senders of 5,000 or more messages a day to Gmail must also publish a DMARC policy and support one-click unsubscribe.

  2. 02

    Yahoo: Sender Hub FAQs. One-click unsubscribe under RFC 8058 for promotional mail, enforced since June 2024. DKIM keys of 1024 bits or greater, 2048 recommended. A published DMARC policy urged on every sending domain. Yahoo states it will not specify a bulk-sender volume threshold.

  3. 03

    RFC 7208: Sender Policy Framework (SPF). The specification for the v=spf1 TXT record this tool reads.

  4. 04

    RFC 6376: DomainKeys Identified Mail (DKIM). The signing scheme and the selector._domainkey record layout that makes DKIM un-guessable without the selector.

  5. 05

    RFC 7489: DMARC. The policy framework behind the p=none, p=quarantine and p=reject values this tool surfaces.

Describe the job once. An agent runs it every week.

Clu turns one sentence into an agent. It searches 1B+ profiles, finds verified emails and phone numbers across 25+ providers, adds the people to your sequence and posts each run to Slack.

An example agent run in Cleanlist AI: Weekly ICP outbound, built by Clu from one sentence.

Weekly ICP outbound

Weekly · Monday 8:00 AM

Ran in 11m 42s

Built by Clu from: “Every week, find 500 new people who match my ICP, get their emails and phones, and add them to Series B outbound.”

  1. Searched 1B+ profiles for new ICP matches500 foundPeople Search
  2. Ran the waterfall across 25+ providers487 emails · 412 phonesWaterfall
  3. Verified every email and phoneSMTP + catch-allVerification
  4. Added them to Series B outbound500 peopleSequences
  5. Posted the run to #pipelineSlackAgents

Friday 4:52 PM15 replies · 5 calls booked

Start free trialSee pricing

14 days of Pro, free: 250 credits, 3 seats, agents, Sequences and Clu in Slack. Then Free at 50 credits a month, or Starter at $49 and Pro at $89 a seat a month.

Now enrich the whole list.

Upload the CSV or ask Clu. Every row comes back with a verified email, a phone number and the company behind the domain.

14 days of Pro, free.