DNS & SPF/DMARC Security Inspector
Zero-Trust Utilities
Tracking this target over time?
This page gives you DNS, SPF and DMARC posture right now. The Recon Workspace saves each scan and shows you what changed since the last one — a new subdomain, a weakened DMARC policy — with the same browser-only guarantee.
What is DNS & SPF/DMARC Security Inspector?
How it works
Features & Benefits
- Zero-Logging: DNS queries are performed browser-to-DoH-provider, avoiding third-party logging of scanned targets
- Email Spoofing Assessment: Instantly flags missing SPF, weak DMARC policies (p=none), or invalid MX records
- Raw DNS data: View resolved records (MX, TXT, A, AAAA, NS) in a clean, developer-friendly interface
- Educational: Explains SPF mechanisms and DMARC alignment rules in plain English
Frequently Asked Questions
How does DNS-over-HTTPS (DoH) preserve privacy?
By querying public DoH APIs directly from your browser, your query is mixed with trillions of other daily DNS resolutions. No middleman website logs your target domains.
Why is a missing DMARC policy dangerous?
Without a DMARC policy (or if the policy is set to p=none), servers receiving mail from your domain will not reject spoofed messages, even if they fail SPF or DKIM checks.
What SPF mechanisms are checked?
We analyze the catch-all mechanism (e.g., -all vs ~all vs +all) and warn you if it's set to +all or missing, which allows anyone to send mail on your behalf.
Related Tools
Scan for active subdomains entirely in your browser using secure DNS-over-HTTPS. Protect your investigation targets from logging.
Check your whole password vault against known breaches without uploading a single password. Uses HIBP k-anonymity for total privacy.
Popular Utilities
Format, validate, and minify JSON instantly in your browser. Your data never leaves your device.
Decode JWT tokens and inspect header and payload instantly in your browser. Your tokens never leave your device.
Count words, characters, sentences, and estimate reading time instantly in your browser. No sign-up required.
Learn More & Guides
Real DNS From a Browser Tab: DoH, CORS, and What You Genuinely Cannot Scan
A browser can resolve real DNS records, brute-force subdomains, and audit mail security without a server. It cannot scan a port. Here is exactly where the line sits, and why.
5 min readSPF, DMARC, and the Grades Nobody Checks
A domain with an SPF record can be completely unprotected against spoofing. Two records is worse than one. And p=none, the most common DMARC policy in the wild, blocks nothing at all.
5 min readWhat Changed Since Tuesday: Recon as a Longitudinal Job
A one-shot scan answers the wrong question. The finding that matters is not which subdomains exist, it is which one appeared last week. That requires storing scans, and getting one field exactly right.
5 min readUsername Sweeps and the Rate-Limit Trap
Checking one handle across eight platforms is easy. The bug worth avoiding is treating every failed request as proof the account does not exist, which is how OSINT tools quietly lie to you.
5 min read