Email deliverability tools that actually work

Live DNS lookups, SMTP verification, and reputation scoring. Not a chatbot rewrite, but real infrastructure checks you can act on.

Loading...

Every free tool

EV
Email Verifier
Check whether one address is real, with a live SMTP handshake
DH
Domain Health Check
SPF, DKIM, DMARC, MX, MTA-STS and BIMI in one pass
BL
Blacklist Checker
Scan 50+ DNSBL zones for a listing against your domain
DI
Domain Intelligence
Trust score, hosting, domain age and reputation profile
ST
Spam Trap Check
Test an address for trap signals before you mail it
DA
DMARC Analyzer
Read the policy you publish and check SPF and DKIM alignment
DG
DMARC Generator
Build a DMARC record and choose an enforcement policy
SC
Spam Score Checker
Score a message against 60+ rules before you send it

You've used your free checks

Create a free SpamCipher account to keep using these tools: unlimited email verification, domain health checks, blacklist scans, and more.

Maybe later

Email Deliverability FAQ

What does SPF, DKIM, and DMARC actually do for my email?

SPF (Sender Policy Framework) is a DNS TXT record that authorizes specific IP addresses to send mail on behalf of your domain. DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each outgoing message so the receiver can verify the message has not been tampered with and was authorized by your domain. DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM together with a policy of none, quarantine or reject, telling receivers what to do when authentication fails. All three together are now required by Gmail and Yahoo for senders sending more than 5,000 messages per day.

Why is my domain or IP on an email blacklist?

Domain and IP blacklists (DNSBLs) like Spamhaus, Barracuda, and SORBS track senders that have triggered spam complaints, sent to spam traps, or shown other reputation-damaging behavior. Common reasons for listing: a compromised account sending spam, an unaltered template ESP IP shared with bad senders, sudden volume spikes from a cold list, or hitting a spam trap address. The Blacklist Scanner shows which of 50+ blacklists currently list you. Most accept delisting requests once you have fixed the underlying issue.

What does a domain trust score actually mean?

The trust score combines multiple infrastructure signals into a single 0–100 number: domain age (older domains carry more trust), DNS authentication completeness (SPF + DKIM + DMARC all configured correctly), blacklist status across 50+ DNSBLs, the hosting provider's reputation, and mail server configuration. A score above 80 typically correlates with inbox placement; below 50 suggests serious configuration gaps that need addressing before sending. Run a full Domain Intelligence report to see your score and the components feeding into it.

Is it safer to use this than uploading my list to a third-party cloud service?

Yes, in two specific ways. (1) These tools work one address or domain at a time, not bulk uploads, so your full subscriber list never touches our infrastructure. (2) The verification results are ephemeral; we do not log the address you check, store the result, or sell anyone's information. Compare to a typical bulk verification service which holds your entire CSV in storage for the duration of the job and often retains anonymized records indefinitely.

Why is the limit 5 free checks per day?

The tools make live SMTP connections, DNS queries, and DNSBL lookups in real time. Each check has a real infrastructure cost on the senders, the resolvers, and the receivers. The 5/day budget keeps the tools available to genuine users while preventing scrapers from exhausting capacity. If you need higher volume, a SpamCipher account adds bulk upload and the real-time validation API, on credits that never expire: one credit per address.

If I fix a DMARC issue, how long until receivers see the change?

DNS propagation typically completes in 5–60 minutes depending on TTL settings, but receivers cache DMARC records aggressively, and most major providers (Gmail, Outlook, Apple) re-fetch every 4–24 hours. Aggregate reports (rua) start arriving the day after the policy change and accumulate over 7–14 days, giving you a clear picture of who is now passing or failing alignment. Use the DMARC Analyzer to confirm the new policy is being served.

Can I check competitors' domains with the deliverability tools?

Yes, the tools only query public DNS and standard authentication records, which are designed to be publicly inspectable. Checking a competitor's SPF, DKIM, DMARC, blacklist status, and trust score is identical to checking your own. The Domain Intelligence tool is specifically designed for this kind of pre-business reputation check.