Email Security Score

Check the public controls protecting your domain's email identity and get a prioritized repair list.

Free · No signup · Read-only public DNS check · Results in seconds

Checks DMARC, SPF, DKIM, MX, MTA-STS, TLS-RPT, and BIMI. It cannot inspect mailbox passwords, private tenant settings, message content, private reputation data, or inbox placement.

--

No Score Just Yet

Your score will appear here once you submit a domain.

What is an Email Security Score?

The Email Security Score is a point-in-time assessment of the public DNS controls protecting a domain's email identity. It checks DMARC, SPF, DKIM, BIMI, MX, MTA-STS, and TLS-RPT, then turns the findings into a 0–100 score and an ordered repair list. It does not inspect mailbox passwords, private provider reputation data, or inbox placement.

DMARCPolicy, reporting, and alignment tags
SPFAuthorized senders and DNS lookup pressure
DKIMPublished selector and public-key evidence
MXPublic inbound-mail routing
MTA-STSPublished transport-security policy
BIMIBrand-indicator record and prerequisites

How the score is calculated

The checker queries the domain's published records and evaluates each control for presence, validity, and safer configuration. Missing or failing SPF, DKIM, and DMARC findings carry the most practical urgency because they affect sender authentication. Transport security, routing, and BIMI findings complete the public-domain picture. The report shows the individual evidence behind the total, so the number never has to be interpreted on its own.

The total and the bands below are Palisade's prioritization model, not an industry certification, provider-compliance verdict, or inbox-placement prediction.

80–100GreatThe main public controls pass, with few or no high-impact gaps.
60–79GoodCore controls are present, but at least one meaningful issue remains.
35–59Needs workImportant public authentication or transport-security gaps remain.
0–34CriticalSeveral foundational controls are missing, invalid, or unenforced.

Example: turn a score into an action plan

Suppose a domain scores 42 because DMARC is still monitoring, one sending service is not represented in SPF, and MTA-STS is missing. The useful output is not “42”; it is the sequence of evidence to verify: identify the real sender, repair SPF or DKIM alignment for that stream, review DMARC reports before enforcement, then add transport security without interrupting inbound mail.

  1. Start with the highest-impact failed finding in the report.
  2. Confirm it against the provider configuration or a real message header.
  3. Change one controlled setting and wait for its DNS TTL.
  4. Re-run the score and preserve the before-and-after evidence.

Use the right follow-up check

Use the focused DMARC checker, SPF checker, or DKIM checker when one published record needs repair. Use the email deliverability test when you need evidence from a message sent through a production stream. Public checks cannot guarantee a receiver's final handling decision.

Technical references

The checks use the public standards for SPF, DKIM, DMARC, MTA-STS, and TLS reporting. BIMI findings follow the current specifications published by the Authenticated Mark Certificates Working Group.

Email authentication knowledge base