Authentication evaluation

DMARC Alignment Lab

Evaluate real SPF and DKIM alignment with the RFC 9989 DNS Tree Walk, or model a hypothetical policy before changing it.

dmarc alignment checkerspf alignmentdkim alignmentdmarc simulator
Evaluate DMARC identity alignment Live mode follows the RFC 9989 DNS Tree Walk. Planning mode models a hypothetical policy without sending mail.

What this analysis does

Live mode discovers the applicable DMARC policy and Organizational Domain through the current RFC 9989 DNS Tree Walk, then evaluates passing SPF and DKIM identifiers against the published alignment modes. Planning mode remains available for hypothetical policy design.

How to use the result

Use real evidence

Paste the exact domain, header, message or configuration. The result is only as useful as the evidence supplied.

Review the findings

Mailybox separates observations from inferred causes so you can see what is known and what still needs verification.

Retest after changes

Email authentication and routing are stateful. Re-run the analysis after publishing a fix.

Interpretation matters

Email systems combine DNS, message-level evidence, provider policy and intermediate infrastructure. A single passing check is not proof that every message will deliver, and a single warning is not proof that a domain is misconfigured. Mailybox is designed to expose the evidence and the relationship between signals so the next action is clear.

Primary references