About this tool

Rather than checking each record type separately, this view is useful when assessing the overall email posture of a domain quickly, for example during supplier due diligence or when triaging a suspected business email compromise.

Example inputs: example.comdigitpol.coma-supplier-domain.com

What the result shows

MX hosts and preference
The mail exchange servers configured to receive mail, in priority order.
SPF
The v=spf1 record listing hosts authorized to send mail for the domain, if published.
DMARC
The _dmarc TXT record stating the requested handling policy for failing mail.
MTA-STS
The _mta-sts TXT record indicating the domain has opted in to enforced TLS for inbound mail delivery.
TLS-RPT
The _smtp._tls TXT record naming where TLS delivery failure reports should be sent.

Investigation use cases

  • Getting a single-screen view of a domain's email security configuration during due diligence
  • Assessing a suspected impersonation domain's mail readiness as part of fraud triage
  • Checking whether a domain has adopted MTA-STS and TLS-RPT alongside SPF and DMARC
  • Documenting a baseline email configuration for a monitored domain

Limitations

This tool reads published DNS policy records only, it does not establish a live TLS connection to the mail servers, does not evaluate a specific message, and does not discover DKIM selectors.

Frequently asked questions

Does this test an actual email delivery to the domain?

No, it only reads published DNS records; no mail is sent and no live connection to the mail server is made.

What does MTA-STS add beyond SPF and DMARC?

MTA-STS is about transport security, requesting that mail delivered to the domain use enforced, validated TLS, which is a separate concern from sender authorization or policy on outbound mail.

Can this find DKIM records?

No, DKIM selectors are not predictable from DNS alone, so DKIM selector discovery is not part of this or any tool here.

Is the lookup free?

Yes, within daily limits; a sealed report is a paid or account feature.

Need evidence you can keep?

Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.