@Mail Domain Check

Diagnostic help

Using the free checks

Run bounded public-DNS and HTTPS-policy checks without an account, mailbox access, or DNS credentials.

Open domain check

Use exact inputs

Domain
Enter a bare domain, not a URL, path, mailbox, or IP address.
DKIM selector
Optional. Use a real selector from the sender configuration or a delivered message header; the tool does not guess.
Sending IP
Optional. Use the actual public SMTP outbound IPv4 or IPv6 address for PTR and forward confirmation.
Data source
The service reads current public DNS and the fixed MTA-STS HTTPS policy path.

Interpret results conservatively

A pass means the observed public configuration met that check. It does not prove inbox placement, sender reputation, message safety, user consent, or future availability.

A DNS or HTTPS lookup error is reported as inconclusive instead of being treated as a missing record. Recheck later before changing production configuration.

Security and data boundaries

  • The tool never needs a mailbox password, DNS credential, private key, or message body.
  • Free analytics retain irreversible hashes and aggregate metrics, not raw domains or sending IPs.
  • A pasted email header is analyzed locally in the browser by the separate header tool.
  • Results intentionally omit raw records, public-key material, and report destinations.

Paid report and delivery

The free check requires no payment. A complete evidence and remediation report can be ordered from the scan results for 1 USDC. Payment accepts only native USDC on Base Mainnet at contract 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913.

Each order has a unique receiving address. The service verifies the recipient, token contract, exact amount, and transaction uniqueness, then delivers only after the transaction reaches Base finalized status. Pending sessions are retained for 7 days. For 30 days after payment, the private recovery link retrieves the full report and reruns the same-domain check after DNS changes; the DKIM selector and actual sending IP can be updated for a recheck. Keep the browser-fragment recovery link confidential.

Errors and limits

Invalid input returns a specific validation message. Rate limiting returns HTTP 429 and a Retry-After value. Temporary DNS, HTTPS, storage, or runtime failures should be retried later.