About this tool
Rather than checking each record type separately, this view is useful when assessing the overall email posture of a domain quickly, for example during supplier due diligence or when triaging a suspected business email compromise.
Example inputs: example.comdigitpol.coma-supplier-domain.com
What the result shows
- MX hosts and preference
- The mail exchange servers configured to receive mail, in priority order.
- SPF
- The v=spf1 record listing hosts authorized to send mail for the domain, if published.
- DMARC
- The _dmarc TXT record stating the requested handling policy for failing mail.
- MTA-STS
- The _mta-sts TXT record indicating the domain has opted in to enforced TLS for inbound mail delivery.
- TLS-RPT
- The _smtp._tls TXT record naming where TLS delivery failure reports should be sent.
Investigation use cases
- Getting a single-screen view of a domain's email security configuration during due diligence
- Assessing a suspected impersonation domain's mail readiness as part of fraud triage
- Checking whether a domain has adopted MTA-STS and TLS-RPT alongside SPF and DMARC
- Documenting a baseline email configuration for a monitored domain
Limitations
This tool reads published DNS policy records only, it does not establish a live TLS connection to the mail servers, does not evaluate a specific message, and does not discover DKIM selectors.
Frequently asked questions
Does this test an actual email delivery to the domain?
No, it only reads published DNS records; no mail is sent and no live connection to the mail server is made.
What does MTA-STS add beyond SPF and DMARC?
MTA-STS is about transport security, requesting that mail delivered to the domain use enforced, validated TLS, which is a separate concern from sender authorization or policy on outbound mail.
Can this find DKIM records?
No, DKIM selectors are not predictable from DNS alone, so DKIM selector discovery is not part of this or any tool here.
Is the lookup free?
Yes, within daily limits; a sealed report is a paid or account feature.
Need evidence you can keep?
Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.
