Is my store's email set up to reach the inbox?
Last updated
Enter the domain your store email is sent from and press Check. SPF, DKIM and DMARC are read from public DNS.
- Your sending domainNeeded
- Your DKIM selector, for a definite DKIM answerOptional
The largest inbox providers introduced bulk-sender rules in 2024 that expect SPF, DKIM and DMARC on any domain sending marketing email. This check reads the public DNS for your domain, the same records a receiving server reads, and stores nothing.
DKIM is best effort without a selector: a few common names are tried, and if none answer the result says not checked rather than missing. Once the email arrives, see how your email capture rate compares.
SPF, DKIM and DMARC in plain terms
Email authentication is three DNS records, SPF, DKIM and DMARC, that let an inbox confirm your store really sent an email, so a store with one SPF record, a DKIM key and a DMARC policy of quarantine passes all three checks.
No benchmark is used. Every verdict is read from the public DNS records for the domain you enter, the same records a receiving server reads. The records only matter if the list is worth sending to: estimate what an email popup could add to it.
Three records, each answering a different question a receiving server asks about every email your store sends. All three live in the DNS for your domain, which is why this check needs nothing but the domain name.
- SPF
- A single TXT record on your domain listing the services allowed to send email as you. Exactly one is allowed: a second SPF record, usually added by a new email tool, breaks both, and receivers then treat the domain as having none.
- DKIM
- A public key your sending service asks you to publish, under a name called a selector. Your email is signed with the matching private key, and the receiver checks the signature against it. Each sending service has its own selector.
- Selector
- The label a DKIM key is filed under, the part before ._domainkey in the record name. DNS gives no way to list them, so this check tries a few common ones and otherwise asks you for yours. It never reports DKIM as missing because a guess did not answer.
- DMARC
- A TXT record under _dmarc on your domain that tells receivers what to do with email that fails SPF and DKIM: nothing (a policy of none), send it to spam (quarantine), or refuse it (reject). It also asks them to send you reports. A subdomain with no DMARC record of its own falls back to the one on its main domain.
- Policy
- The instruction inside DMARC. None is monitoring only: it meets the requirement to publish a record but protects nothing. Quarantine and reject are enforcement, and are what stop someone else sending email that claims to be from your store.
Nudgesmart is available on the Shopify App Store. Browse the template library or see what it costs.
Eight domains, eight different DNS answers
Illustrative DNS results on reserved example domains, not any real store. Every verdict is produced by the same function that reads a live check.
| Scenario | SPF | DKIM | DMARC | Verdict |
|---|---|---|---|---|
| All three published, DMARC set to reject | One record | Found: s1 | Enforced: reject | All three in place |
| DMARC published but left on monitoring | One record | Found: default | Monitoring only | Published, not enforced |
| No DMARC record at all | One record | Found: k1 | Missing | One record needs fixing |
| A second email tool added its own SPF record | 2 records, broken | Found: selector1 | Enforced: quarantine | One record needs fixing |
| Selector not given and none of the common ones answer | One record | Not checked | Enforced: quarantine | DKIM not checked yet |
| SPF that allows every server | Allows anyone | Found: mail | Monitoring only | One record needs fixing |
| Old DKIM key revoked and never replaced | One record | Key revoked | Enforced: reject | One record needs fixing |
| Misspelt domain | n/a | n/a | n/a | Domain not found |
What a DNS check cannot see
Passing all three is not the same as reaching the inbox
Authentication proves the email is yours. Whether it lands in the inbox also depends on your sending reputation, how many people open, ignore or report it, and whether the list was collected with consent. A domain can be set up perfectly and still land in spam.
Alignment is not checked here
DMARC passes only when SPF or DKIM passes for the same domain the shopper sees in the From line. A record can exist and still not align, for example when a sending service signs with its own domain. Your DMARC reports show alignment; a DNS lookup cannot.
DKIM is best effort without your selector
The check tries a short list of common selector names. If your sending service uses a different one, DKIM reads as not checked, which says nothing about whether it is set up. Enter the selector from your sending service settings for a definite answer.
SPF includes are not followed
An SPF record can pull in other records, and receivers stop following them after a fixed number of lookups. This check confirms there is exactly one SPF record and that it ends in a soft or hard fail rather than allowing every server or leaving them neutral; it does not walk the chain to count lookups or confirm each sender is listed.
DNS changes take time to show
A record you added a few minutes ago may not be visible to every resolver yet. If a check disagrees with what your DNS host shows, wait and run it again rather than adding the record a second time, which is how duplicate SPF records usually happen.
Store email authentication questions
Do I need SPF, DKIM and DMARC for my store email?
Yes, if your store sends marketing email at any volume. The largest inbox providers introduced bulk-sender rules in 2024 that expect all three, and email that fails them is more likely to be filtered or refused. Email your store platform sends from its own domain is covered by the platform records; anything sent from your own domain depends on yours.
Why does it say DKIM was not checked?
Because DKIM keys are filed under a selector name only your sending service knows, and there is no way to list them from DNS. The check tries common names; if none answer, it asks for yours rather than guessing that DKIM is missing. Your sending service shows the selector in the DNS records it asked you to add.
What DMARC policy should I use?
Start with a policy of none and a reporting address so you can see who sends email as your domain. Once the reports show every service you use passing, move to quarantine, and to reject when you are confident. Staying on none indefinitely meets the requirement to publish a record but leaves your domain open to spoofing.
Which domain should I enter?
The one after the @ in the From address your newsletters and flows are sent from, not your store web address if the two differ. SPF and DKIM are checked on that exact domain, so a record on your main domain does not cover a sending subdomain. DMARC is the exception: a subdomain with no record of its own falls back to the main domain, and the result says which one applied.
I have two SPF records. Is that a problem?
Yes. More than one SPF record is an error, and receiving servers treat it as if you had none. It usually happens when a second email tool tells you to add its own record. Merge them into one record that includes every sending service.
Does this check change anything or need access to my store?
No. It reads public DNS records for the domain you enter, the same records any receiving server reads, and changes nothing. There is no account, no install and no store connection, and the domain is not stored.
An inbox-ready domain with nobody to send to is half a setup.
Nudgesmart captures the address on your storefront from a ready-made template and reports email captures per campaign.