Free real-message check
Send a real email. See its health scorecard here.
Get a private test address, send from the setup you actually use, and see a graded breakdown of authentication signals and selected message-level checks.
What this scorecard can prove
DKIM is checked against the message itself: signed headers and body are canonicalized, the public key is fetched from DNS, and the signature is verified according to RFC 6376. The report also checks whether the signing domain aligns with the visible From address, which is the relationship DMARC evaluates.
SPF and DMARC publication signals are read from public DNS. For SPF, the scorecard only reports whether a TXT value begins with v=spf1; it does not validate syntax, duplicate records, DNS lookup limits, or a live result for this message. Selected message-level checks include the one-click unsubscribe mechanism defined by RFC 8058 and keep advisory findings separate from cryptographic results.
This is a deliverability foundation check, not an inbox-placement promise. Provider reputation, complaint rates, engagement, list quality, and each recipient's private filtering remain outside what any external scorecard can prove.
Common questions
How does the email deliverability test work?+
Generate a private test address, send a normal email from the account or campaign tool you actually use, and keep the report page open. A Cloudflare Email Worker verifies the message's DKIM signature and alignment, checks for SPF and DMARC publication signals, and analyzes selected message-level properties. The scorecard appears in your browser without relying on a reply email.
Is the DKIM check a real cryptographic verification?+
Yes. We parse the DKIM-Signature header on the message, canonicalize the signed headers and body as RFC 6376 specifies, fetch the public key from DNS, and verify the signature. We also compare the signing domain with the visible From address for DMARC alignment.
What do the selected message-level checks inspect?+
They inspect one-click unsubscribe headers, a plain-text alternative, image-to-text balance, HTML size against Gmail's clipping threshold, and common spam-signal issues in the subject line. These are observable message signals, not a complete bulk-sender compliance assessment.
Does this prove that my email reaches the inbox?+
No. No external tool can guarantee inbox placement because Gmail, Yahoo, Microsoft, and other providers use private filters plus recipient-specific reputation and engagement signals. This test verifies the authentication and message-level foundations we can directly observe; it does not pretend to simulate a recipient's spam folder.
Why is SPF reported as a publication signal rather than pass or fail?+
A live SPF verdict depends on the sending IP seen by the receiving mail server, which the receiving platform does not expose to this Worker. The scorecard only reports whether it found a TXT value beginning with v=spf1; it does not validate SPF syntax, duplicate records, DNS lookup limits, or a message-specific result.
I sent an email but the report did not appear. What happened?+
Confirm that you sent to the exact private test address shown on the page and allow up to three minutes for delivery. The private report ID is already in the page URL, so you can reload or retry waiting without needing an automated reply.
How long is my report stored?+
The private report URL remains available for 7 days and is then automatically deleted. Anyone with that hard-to-guess URL can view the report during that window, so share it only with people you trust.