← All tools
Email & DNS Tool

Email DNS Authentication Checker

Review pasted SPF and DMARC records for common structural mistakes before a website or DNS migration.

Free to useNo account requiredRuns in your browser
Planning result
—

Enter your site details and calculate.

How to use this email dns authentication checker

This free utility is designed for migration planning. It turns a few operational inputs into a structured result so you can identify what should be checked before a production change. It does not connect to your server, registrar, DNS provider or WordPress database, so it cannot replace a real technical audit.

This is a syntax review, not a live DNS lookup

The tool checks the text you paste for common structural problems. It does not prove that the record is published, that included SPF hosts resolve, or that mail is aligned correctly.

SPF must reflect real senders

Your website host, transactional mail provider, Google Workspace, Microsoft 365, CRM and other senders may all affect SPF design. Copy the exact mechanisms from those providers.

DMARC depends on SPF or DKIM alignment

A DMARC policy is effective only when legitimate mail can authenticate and align. Move gradually from monitoring to enforcement after reviewing reports.

Preserve DKIM during migration

DKIM keys and selectors come from the sending platform. If email stays with the same provider during a website migration, those records usually should not be changed.

Important limitations

Does this tool change anything on my website?

No. It runs locally in the browser and only evaluates the values you enter. It does not log in to WordPress, connect to DNS, move files or modify hosting.

Can I use the result as a production checklist?

Use it as a starting checklist. Add the site-specific dependencies discovered during the source audit, including custom plugins, server rules, cron jobs, email, APIs, payment gateways and any third-party services.

When is manual migration planning necessary?

Manual planning is appropriate when the site generates revenue, has active customer data, cannot tolerate downtime, uses custom server configuration, has a large database or depends on integrations outside WordPress.

Professional interpretation

How to use Email DNS Authentication Checker in a real WordPress project

The useful part of a planning tool is not the number by itself. It is understanding which assumptions produced the result, which production conditions can change it, and what should be checked before you act. Use this tool as part of a wider migration or infrastructure review rather than as an automatic go/no-go decision.

DNS changes affect more than the website

A domain can carry website routing, mail delivery, verification records, subdomains, third-party SaaS records and security policies. Review the full zone before changing nameservers or replacing records.

TTL is a cache instruction, not a global timer

Recursive resolvers and client caches do not all update at one exact moment. Lower TTL before a planned cutover when possible, then keep the old origin available long enough to absorb straggling traffic.

Email deserves a separate verification pass

MX, SPF, DKIM and DMARC should be checked independently of the website. A migration can appear successful in the browser while business email is silently misrouted or authentication begins failing.

Practical questions

Will everyone see a DNS change when TTL expires?

Not necessarily. TTL influences caching, but resolver behavior and previously cached answers vary.

Can nameserver changes break email?

Yes if the new DNS zone does not reproduce the required MX and authentication records.

Should the old server remain online?

Usually for a reasonable overlap period, especially while DNS propagation and cached traffic settle.