Use exact inputs
- Domain
- Enter a bare domain, not a URL, path, mailbox, or IP address.
- DKIM selector
- Optional. Use a real selector from the sender configuration or a delivered message header; the tool does not guess.
- Sending IP
- Optional. Use the actual public SMTP outbound IPv4 or IPv6 address for PTR and forward confirmation.
- Data source
- The service reads current public DNS and the fixed MTA-STS HTTPS policy path.
Interpret results conservatively
A pass means the observed public configuration met that check. It does not prove inbox placement, sender reputation, message safety, user consent, or future availability.
A DNS or HTTPS lookup error is reported as inconclusive instead of being treated as a missing record. Recheck later before changing production configuration.
Security and data boundaries
- The tool never needs a mailbox password, DNS credential, private key, or message body.
- Free analytics retain irreversible hashes and aggregate metrics, not raw domains or sending IPs.
- A pasted email header is analyzed locally in the browser by the separate header tool.
- Results intentionally omit raw records, public-key material, and report destinations.
Paid report and delivery
The free check requires no payment. A complete evidence and remediation report can be ordered from the scan results for 1 USDC. Payment accepts only native USDC on Base Mainnet at contract 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913.
Each order has a unique receiving address. The service verifies the recipient, token contract, exact amount, and transaction uniqueness, then delivers only after the transaction reaches Base finalized status. Pending sessions are retained for 7 days. For 30 days after payment, the private recovery link retrieves the full report and reruns the same-domain check after DNS changes; the DKIM selector and actual sending IP can be updated for a recheck. Keep the browser-fragment recovery link confidential.
Errors and limits
Invalid input returns a specific validation message. Rate limiting returns HTTP 429 and a Retry-After value. Temporary DNS, HTTPS, storage, or runtime failures should be retried later.