---
title: "DNS Security Scanner"
description: "Scan DNS records for email security configurations including SPF, DKIM, DMARC, MX records, and more. Ensure your domain is protected against email spoofing."
url: https://findutils.com/network/dns-security-scanner/
category: network
---

# DNS Security Scanner

Scan DNS records for email security configurations including SPF, DKIM, DMARC, MX records, and more. Ensure your domain is protected against email spoofing.

**Use this tool:** [DNS Security Scanner](https://findutils.com/network/dns-security-scanner/)

## Programmatic access

- REST id `dns-security-scanner`: POST https://api.findutils.com/api/tools/dns-security-scanner/execute (reference: https://findutils.com/api/dns-security-scanner/)
- MCP tool `dns_security_scanner` on https://mcp.findutils.com (reference: https://findutils.com/mcp/dns-security-scanner/)

## Why Scan DNS Security?

Properly configured DNS records protect your domain from email spoofing and phishing attacks. SPF, DKIM, and DMARC work together to authenticate email and protect your brand.

## DNS Security Best Practices

- Always set your DMARC policy to 'quarantine' or 'reject' after verifying legitimate senders pass authentication checks.
- Limit your SPF record to fewer than 10 DNS lookups to avoid exceeding the specification limit, which causes SPF to fail.
- Add a CAA record to restrict which certificate authorities can issue SSL certificates for your domain.
- Configure DMARC aggregate reporting (rua) to receive regular reports about email authentication results for your domain.
- Rotate DKIM keys at least once per year and use 2048-bit keys for stronger cryptographic security.

## Frequently Asked Questions

### What is SPF?

Sender Policy Framework (SPF) specifies which mail servers are authorized to send email for your domain, preventing spoofing.

### What is DKIM?

DomainKeys Identified Mail (DKIM) adds a digital signature to emails, allowing recipients to verify the message wasn't altered in transit.

### What is DMARC?

Domain-based Message Authentication, Reporting & Conformance (DMARC) tells receivers how to handle emails that fail SPF or DKIM checks.

### Why are all three needed?

SPF, DKIM, and DMARC complement each other. Together they provide comprehensive email authentication and deliverability.

### What is a CAA record and why does it matter?

A Certificate Authority Authorization (CAA) record specifies which certificate authorities are permitted to issue SSL/TLS certificates for your domain. Without a CAA record, any CA can issue a certificate, increasing the risk of unauthorized certificate issuance.

### How often should I scan my DNS security records?

Scan your DNS records at least once per quarter and after any changes to your email infrastructure, mail provider migrations, or DNS zone edits. Regular scanning catches misconfigurations before they lead to deliverability problems or spoofing incidents.

### What does a DMARC policy of 'none' mean?

A DMARC policy set to 'none' means receiving mail servers will not take action on emails that fail authentication. It is useful for monitoring during initial deployment, but should be upgraded to 'quarantine' or 'reject' once you confirm legitimate email passes SPF and DKIM checks.

### Why does my SPF record fail with too many lookups?

The SPF specification limits DNS lookups to 10 per evaluation. Each 'include', 'a', 'mx', and 'redirect' mechanism triggers a lookup. Exceeding this limit causes SPF to return a permanent error, effectively disabling SPF protection for your domain.

### Does this DNS security scanner require a signup?

No. The FindUtils DNS Security Scanner is available with no account registration, no usage limits, and no restrictions on the number of domains you can scan.

### Can I scan subdomains with this tool?

Yes, you can scan any subdomain by entering it directly (e.g. mail.example.com). Each subdomain may have its own SPF, DMARC, and MX records that differ from the root domain.

### What leaves my device when I scan a domain?

The domain name. The page asks Cloudflare's DNS-over-HTTPS resolver for the domain's TXT, MX, and CAA records and its _dmarc TXT record, five queries in total, directly from your browser. FindUtils servers do not receive the domain, and the page stores nothing. Cloudflare sees the queries as it would from any DNS client.

## Related Tools

- [Email Security Checker](https://findutils.com/security/email-security-checker/)
- [SSL Certificate Checker](https://findutils.com/network/ssl-certificate-checker/)
- [Security Headers Analyzer](https://findutils.com/network/security-headers-analyzer/)
- [DNS Lookup](https://findutils.com/network/dns-lookup/)
- [Email Validator](https://findutils.com/security/email-validator/)
- [URL Safety Checker](https://findutils.com/security/url-safety-checker/)
- [Cookie Analyzer](https://findutils.com/security/cookie-analyzer/)
- [Privacy Policy Checker](https://findutils.com/security/privacy-policy-checker/)
