MXToolbox
Popular DNS and mail diagnostics suite for SPF, DMARC, blacklist, and MX checks.
- Reading time:
- 5 min
- Difficulty:
- Intermediate
- Estimated duration:
- 5 min
- Prerequisites:
- None
- Last updated:
- 2026-07-15
- Author:
- empire
Overview
Popular DNS and mail diagnostics suite for SPF, DMARC, blacklist, and MX checks.
Vendor: MxToolbox
Primary purpose
Inspect mail DNS, authentication records, and common reputation blocklists from one place.
Best for
- Operators verifying SPF/DMARC/MX quickly
- First-pass blacklist and DNS diagnostics
Common use cases
- Validate SPF and DMARC after DNS edits
- Check whether a sending IP appears on common blocklists
- Confirm MX targets during migration
Advantages
- Broad, familiar diagnostic coverage
- Fast shared links for incident response
Limitations
- UI and free limits change over time
- Not a substitute for provider postmaster reputation views
When not to use it
- You need continuous inbox-placement sampling
- You need a full DMARC aggregate reporting platform
Pricing
Free lookups with paid monitoring tiers.
Official website
Inputs and outputs
Typical inputs
- Domain
- IP
- Optional record type
Typical outputs
- Lookup reports
- Pass/fail indicators
- Blocklist hits
Privacy notes
- Review each vendor’s data handling before uploading production lists or message content.
Related Learn Articles
Related Solve Articles
- SPF record missingNo SPF TXT record is published for the sending domain.
- DMARC record missingNo DMARC TXT record exists at the organizational domain.
- Reverse DNS mismatchPTR (reverse DNS) for a sending IP is missing or does not match the forward hostname used in mail.
- Broken SPF includeAn included SPF domain is missing, invalid, or fails closed.
- Forwarded email fails SPFForwarding paths break SPF because the forwarder is not authorized.
- Incorrect IP authorizationSending infrastructure IPs are not authorized by SPF.
- Invalid SPF mechanismSPF record contains unsupported or malformed mechanisms.
- Multiple SPF recordsMore than one SPF TXT record exists, causing evaluation failure.
- SPF passes but DMARC failsSPF authenticates a domain that does not align for DMARC.
- SPF PermErrorSPF evaluation fails permanently due to policy or lookup errors.
- SPF TempErrorTemporary DNS or evaluation failure during SPF checks.
- Too many DNS lookupsSPF evaluation exceeds the ten-lookup limit.
- DMARC alignment failureSPF/DKIM pass but fail identifier alignment.
- DMARC policy not appliedPublished policy is not observed as expected by receivers.
- DMARC reports not arrivingAggregate or failure reports are not received.
- External reporting not authorizedExternal rua/ruf destinations lack DNS authorization.
- Invalid DMARC syntaxDMARC record cannot be parsed by receivers.
- Legitimate mail blocked after enforcementEnforcement blocks wanted senders still failing authentication.
- Subdomains not protectedSubdomain traffic is outside effective DMARC coverage.
- Unknown senders in DMARC reportsReports show sources not yet inventoried or authorized.
- CNAME at zone apexA CNAME is placed at the zone apex where other record types are also required.
- HELO / EHLO problemsThe SMTP HELO/EHLO hostname is missing, invalid, or inconsistent with reverse DNS.
- Inconsistent authoritative answersAuthoritative name servers for the same zone return conflicting data.
- Incorrect MX targetMX points to the wrong host name or unreachable mail server.
- Missing glue recordsDelegation references in-bailiwick name servers without required glue.
- MX record missingNo MX record is published for a domain that should receive mail.
- NXDOMAIN for expected nameA name that should exist returns NXDOMAIN from authoritative servers.
- Stale DNS cache after changeResolvers still serve prior answers after an authoritative change because TTL has not expired.
- Wrong TTL for cutoverTTL values are too high for a planned cutover, prolonging mixed old/new answers.
Alternatives & related tools
- digCLI DNS lookup utility for authoritative and recursive inspection of mail-related records.
- Kitterman SPF validatorClassic web SPF policy evaluator used by operators for syntax checks.
- Mail-TesterSend-a-message spam and authentication scoring for pre-send QA.
- dmarcian inspectorsDMARC-focused inspectors and educational tooling from dmarcian.
- EasyDMARC free toolsFree DMARC/SPF/DKIM lookup and analysis utilities from EasyDMARC.
- PowerDMARC free analyzersFree authentication analyzers from PowerDMARC for SPF, DKIM, and DMARC.
- LearnDMARCInteractive DMARC learning and inspection helper for operators new to enforcement.
- URIports toolsDMARC and related reporting tools for operators collecting aggregate feedback.
- nslookupInteractive DNS lookup utility commonly used for quick MX and TXT checks.
- Google Admin Toolbox DigBrowser-based dig-style DNS lookup from Google’s Admin Toolbox.
- Google Admin Toolbox CheckMXGoogle Admin Toolbox Check MX for inbound mail DNS sanity checks.
Related Workflows
- Verify DNS recordsVerify zone authority, MX/address records, and authentication-related TXT publications.
- Authenticate a new domainPublish SPF, DKIM, and DMARC for a new sending domain and verify authentication before warmup.
- Configure SPFPublish and validate an SPF policy for authorized senders.
- Migrate authentication recordsMove SPF, DKIM, and DMARC to a new platform without dual-record failures.
- Configure DMARCPublish DMARC at monitoring policy and validate reporting.
- Audit multi-domain authenticationReview authentication across a domain portfolio.
- Check authenticationRegularly verify SPF, DKIM, and DMARC alignment and report pipelines.