Grow & email your list · Checkers · Free tool

Is my store's email set up to reach the inbox?

Last updated

Email authentication—
Step 1 of 2
What domain does your store email come from?

The part after the @ in the address your newsletters and flows are sent from.

A store address or an email address works too; it is trimmed to the domain.

Step 2 of 2
Do you know your DKIM selector?

Optional. Without it a few common names are tried, and DKIM reads as not checked if none answer.

Shown in your sending service DNS settings: the part before ._domainkey in the record name.

Email authentication

Enter the domain your store email is sent from and press Check. SPF, DKIM and DMARC are read from public DNS.

  • Your sending domainNeeded
  • Your DKIM selector, for a definite DKIM answerOptional

The largest inbox providers introduced bulk-sender rules in 2024 that expect SPF, DKIM and DMARC on any domain sending marketing email. This check reads the public DNS for your domain, the same records a receiving server reads, and stores nothing.

DKIM is best effort without a selector: a few common names are tried, and if none answer the result says not checked rather than missing. Once the email arrives, see how your email capture rate compares.

SPF, DKIM and DMARC in plain terms

Email authentication is three DNS records, SPF, DKIM and DMARC, that let an inbox confirm your store really sent an email, so a store with one SPF record, a DKIM key and a DMARC policy of quarantine passes all three checks.

No benchmark is used. Every verdict is read from the public DNS records for the domain you enter, the same records a receiving server reads. The records only matter if the list is worth sending to: estimate what an email popup could add to it.

Three records, each answering a different question a receiving server asks about every email your store sends. All three live in the DNS for your domain, which is why this check needs nothing but the domain name.

SPF
A single TXT record on your domain listing the services allowed to send email as you. Exactly one is allowed: a second SPF record, usually added by a new email tool, breaks both, and receivers then treat the domain as having none.
DKIM
A public key your sending service asks you to publish, under a name called a selector. Your email is signed with the matching private key, and the receiver checks the signature against it. Each sending service has its own selector.
Selector
The label a DKIM key is filed under, the part before ._domainkey in the record name. DNS gives no way to list them, so this check tries a few common ones and otherwise asks you for yours. It never reports DKIM as missing because a guess did not answer.
DMARC
A TXT record under _dmarc on your domain that tells receivers what to do with email that fails SPF and DKIM: nothing (a policy of none), send it to spam (quarantine), or refuse it (reject). It also asks them to send you reports. A subdomain with no DMARC record of its own falls back to the one on its main domain.
Policy
The instruction inside DMARC. None is monitoring only: it meets the requirement to publish a record but protects nothing. Quarantine and reject are enforcement, and are what stop someone else sending email that claims to be from your store.

Nudgesmart is available on the Shopify App Store. Browse the template library or see what it costs.

Eight domains, eight different DNS answers

Illustrative DNS results on reserved example domains, not any real store. Every verdict is produced by the same function that reads a live check.

Worked examples: illustrative DNS answers for SPF, DKIM and DMARC, and the verdict each produces
ScenarioSPFDKIMDMARCVerdict
All three published, DMARC set to rejectOne recordFound: s1Enforced: rejectAll three in place
DMARC published but left on monitoringOne recordFound: defaultMonitoring onlyPublished, not enforced
No DMARC record at allOne recordFound: k1MissingOne record needs fixing
A second email tool added its own SPF record2 records, brokenFound: selector1Enforced: quarantineOne record needs fixing
Selector not given and none of the common ones answerOne recordNot checkedEnforced: quarantineDKIM not checked yet
SPF that allows every serverAllows anyoneFound: mailMonitoring onlyOne record needs fixing
Old DKIM key revoked and never replacedOne recordKey revokedEnforced: rejectOne record needs fixing
Misspelt domainn/an/an/aDomain not found
Row four is the one that catches stores out. Each email tool asks you to add its own SPF record, and the second one silently breaks the first: two records read as none. Row five is not a fail at all. DKIM could not be checked without a selector, and the page says so instead of guessing.

What a DNS check cannot see

Passing all three is not the same as reaching the inbox

Authentication proves the email is yours. Whether it lands in the inbox also depends on your sending reputation, how many people open, ignore or report it, and whether the list was collected with consent. A domain can be set up perfectly and still land in spam.

Alignment is not checked here

DMARC passes only when SPF or DKIM passes for the same domain the shopper sees in the From line. A record can exist and still not align, for example when a sending service signs with its own domain. Your DMARC reports show alignment; a DNS lookup cannot.

DKIM is best effort without your selector

The check tries a short list of common selector names. If your sending service uses a different one, DKIM reads as not checked, which says nothing about whether it is set up. Enter the selector from your sending service settings for a definite answer.

SPF includes are not followed

An SPF record can pull in other records, and receivers stop following them after a fixed number of lookups. This check confirms there is exactly one SPF record and that it ends in a soft or hard fail rather than allowing every server or leaving them neutral; it does not walk the chain to count lookups or confirm each sender is listed.

DNS changes take time to show

A record you added a few minutes ago may not be visible to every resolver yet. If a check disagrees with what your DNS host shows, wait and run it again rather than adding the record a second time, which is how duplicate SPF records usually happen.

Store email authentication questions

Do I need SPF, DKIM and DMARC for my store email?

Yes, if your store sends marketing email at any volume. The largest inbox providers introduced bulk-sender rules in 2024 that expect all three, and email that fails them is more likely to be filtered or refused. Email your store platform sends from its own domain is covered by the platform records; anything sent from your own domain depends on yours.

Why does it say DKIM was not checked?

Because DKIM keys are filed under a selector name only your sending service knows, and there is no way to list them from DNS. The check tries common names; if none answer, it asks for yours rather than guessing that DKIM is missing. Your sending service shows the selector in the DNS records it asked you to add.

What DMARC policy should I use?

Start with a policy of none and a reporting address so you can see who sends email as your domain. Once the reports show every service you use passing, move to quarantine, and to reject when you are confident. Staying on none indefinitely meets the requirement to publish a record but leaves your domain open to spoofing.

Which domain should I enter?

The one after the @ in the From address your newsletters and flows are sent from, not your store web address if the two differ. SPF and DKIM are checked on that exact domain, so a record on your main domain does not cover a sending subdomain. DMARC is the exception: a subdomain with no record of its own falls back to the main domain, and the result says which one applied.

I have two SPF records. Is that a problem?

Yes. More than one SPF record is an error, and receiving servers treat it as if you had none. It usually happens when a second email tool tells you to add its own record. Merge them into one record that includes every sending service.

Does this check change anything or need access to my store?

No. It reads public DNS records for the domain you enter, the same records any receiving server reads, and changes nothing. There is no account, no install and no store connection, and the domain is not stored.

Get started

An inbox-ready domain with nobody to send to is half a setup.

Nudgesmart captures the address on your storefront from a ready-made template and reports email captures per campaign.

SPF, DKIM & DMARC Checker for Shopify | Nudgesmart