Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallTo catch email DNS problems before clients report bounced messages, start with the full bounce notice, identify which system sent the email, then compare your live MX, SPF, DKIM and DMARC records with the current instructions for your mail host and every service that sends mail for your domain. DNS is only one possible cause of a rejection, so use the bounce’s SMTP code and diagnostic text to guide the check rather than changing records blindly.
Start with the bounce notice, not a DNS change
Save the complete non-delivery report (NDR), also called a bounceback. Record the SMTP status code, the receiving provider’s diagnostic text, the recipient address and provider, the time, and the service that sent the message. Those details help distinguish an authentication or DNS problem from a recipient-side policy decision or another delivery failure. Google explains how to interpret common bounce messages in its bounce guidance; Microsoft also describes interpreting authentication-related failures in its Microsoft 365 troubleshooting guide.
Use the failure context to choose what to check first:
- Incoming mail is not arriving: check whether the domain’s MX records point to the current incoming-mail provider.
- Outgoing mail is rejected or marked unauthenticated: check the sending system, SPF, DKIM and DMARC.
- Only one service or message type fails: include that service—such as a website form, CRM, ticketing platform or marketing system—in the investigation. It may send through a different route from ordinary staff email.
Keep the original NDR intact when escalating to your mail host. A paraphrase can omit the status code or receiver-specific clue needed to diagnose the rejection.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
Know what each DNS record does
MX, SPF, DKIM and DMARC address different parts of mail delivery and authentication; they are not interchangeable. Microsoft’s mail-flow overview describes these records in the context of Microsoft 365 and Office 365. The values to publish depend on your provider and configuration, so use that provider’s current setup instructions rather than copying a record from another organization.
| Record | What it does | What to verify |
|---|---|---|
| MX | Directs incoming mail for a domain to its mail host. | That it points to the current incoming-mail provider and matches that provider’s instructions. |
| SPF | Lists sending sources authorized to send mail for a domain. | That the record includes the services actually sending mail and that the domain does not have multiple SPF records. |
| DKIM | Publishes a public key that receiving systems use to verify a message signature. | That the selector record exists, its public key matches the sending platform’s configuration, and the platform is signing messages. |
| DMARC | Specifies how receivers should handle authentication failures and checks whether SPF or DKIM authenticates mail in alignment with the visible From domain. | That a DMARC record is published and at least one passing authentication method aligns with the From domain. |
Check SPF for missing senders and record errors
SPF problems often surface after adding or changing a service that sends as your domain. Compare the SPF record with every active sender, including business mail, website forms, CRMs, ticketing systems and marketing platforms. Add a sender only with the vendor’s current SPF instructions.
Rank #2
- Look for a missing or unauthorized sending service.
- Check for more than one SPF record for the domain. Do not fix an omission by blindly publishing a second one.
- Review the record for syntax mistakes and the SPF DNS-lookup-limit error. Microsoft’s Microsoft 365 troubleshooting guide describes a limit of 10 DNS lookups for SPF evaluation; the exact record design should follow your provider’s guidance.
If a sender was recently introduced, confirm which domain it uses for its envelope sender and what SPF change its vendor requires. Do not assume that a service’s own successful authentication means it is authorized or aligned for your visible From address.
Check DKIM’s selector and actual message signing
DKIM depends on both a published DNS key and the sending service’s configuration. Find the selector specified by the service and verify that its DNS record exists and contains the matching public key. Then confirm that the platform is signing outgoing messages. A DNS record alone does not prove that a message was signed.
Recommended Free Tools
Rank #3
If a message is signed but DKIM fails, check whether a mail gateway or other intermediary changed signed content in transit. Use the authentication results in the received message headers, along with the NDR and the sending platform’s instructions, to narrow down where the failure occurs.
Check DMARC alignment, not just pass or fail labels
A passing SPF or DKIM result by itself does not guarantee that DMARC passes. DMARC requires at least one of those mechanisms to pass and align with the domain shown in the message’s From address. A third-party service can authenticate its own envelope domain or signing domain successfully without aligning that domain to your visible From domain.
Rank #4
When a bounce or message header indicates a DMARC failure, compare the authenticated domains shown for SPF and DKIM with the From domain. If neither passing mechanism aligns, follow the mail provider’s current configuration instructions for the sending service and your DMARC policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Apply recipient-provider requirements to the right mail
Requirements differ by receiving provider. Google’s published Gmail sender guidelines apply to mail sent to personal Gmail accounts, not as a universal rule for every recipient. Google defines bulk senders as those sending more than 5,000 messages per day to Gmail accounts and requires SPF, DKIM and DMARC for those senders, with alignment required for direct mail. The same guideline recommends keeping the Gmail spam rate below 0.10% and avoiding 0.30% or higher; those are spam-rate targets, not DNS-record health thresholds.
Check the recipient provider’s own current guidance when investigating a rejection. Do not apply a Gmail-specific threshold or requirement to other providers without evidence that it applies.
Quick Recap
Verify the correction and monitor delivery
- Compare live DNS with current provider instructions. Check the domain’s records against the mail host’s setup guide and each authorized sender’s documentation. Make sure the records belong to the domain and selector the service actually uses.
- Use provider diagnostics. Google points senders to Admin Toolbox to review domain settings. Microsoft documents message-header analysis, message trace and Remote Connectivity Analyzer for relevant Microsoft 365 checks in its authentication troubleshooting guide.
- Send a new test and inspect its result. Review authentication results and actual delivery after the DNS change. A checker can show evidence about configuration, but it cannot guarantee inbox placement or explain every receiver-side rejection.
- If rejection continues, escalate with evidence. Give your email host the unchanged NDR, the affected recipient and timestamp, the sending service, and any relevant message-header results. Receiver policy, reputation, message formatting, transport security or sender configuration may be involved even when DNS appears correct.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




