One request audits SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and DNSSEC — and tells you exactly what to change. Free for one domain; built to audit thousands.
Free, no signup. Reads public DNS only — nothing is sent on your behalf.
Most tools read a record and tell you whether it parses. The failures that actually break email are the ones where the record parses perfectly and still doesn’t work. Four things this does differently:
SPF allows ten DNS lookups, counting everything inside nested include:
chains. A one-level check says your record is valid. This one follows every include,
counts the real total, and shows you the chain — because at eleven, receivers act as
though you have no SPF at all.
Checking that the TXT record exists proves nothing. This retrieves the policy file over
HTTPS and validates it — catching the 404s, redirects, bad certificates and
mode: testing that make receivers silently ignore your policy.
DKIM selectors can’t be enumerated from DNS, so “no DKIM found” is a guess in any tool. This one says which selectors it tried. Requirements that depend on your mail rather than your DNS are marked unverifiable instead of being given a green tick they haven’t earned.
SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and DNSSEC in a single call — as JSON with a severity, the underlying records, and a specific fix per finding. Built to run in a pipeline, not to be read in a browser.
Don’t take our word for it. Run your domain above, then run it through whatever you use today. If we surface something they didn’t, that’s the difference. If we don’t, keep what you have.
If you look after a single domain, the free tier covers you — checking it every hour all month uses about 720 of your 1,000 requests. The paid plans exist for people auditing many domains:
Check every client domain on a schedule and catch it the day someone edits DNS and breaks SPF. 150 client domains checked daily is about 4,500 requests a month.
Qualify a customer’s sending domain at signup, and re-check periodically. Bad sender setup becomes your deliverability problem — catch it before the first send.
A domain without enforced DMARC can be spoofed. Score a supplier list, an acquisition target, or your own estate, and track it over time.
Zero marginal cost means volume is cheap here — the largest plan works out under $0.0004 per domain audited.
Plain JSON, no SDK, no auth ceremony to try it.
curl "https://postureaudit.com/v1/audit?domain=example.com"
{
"domain": "example.com",
"score": 72,
"grade": "C",
"sections": [ { "name": "SPF", "status": "warn", "findings": [ … ] } ],
"compliance": { "compliant": false, "items": [ … ] }
}
Every finding carries a status, a severity, the DNS records the verdict came from, and a specific fix. Full reference in the interactive API docs.
Plain explanations of the failures that break email authentication quietly.
Why exceeding ten lookups makes receivers ignore SPF entirely, and four ways to get back under.
Selectors can’t be enumerated from DNS. How to find yours, and what an empty p= means.
A policy in DNS with no reachable file is silently ignored. The four things that break it.
Which requirements are verifiable from DNS, and which depend on the mail you send.
A working script to sweep every client domain on a schedule and alert only on what changed.
Monitor a portfolio of domains, or audit them on signup. Cancel anytime.
Every plan runs the same checks — higher tiers buy volume, not features. Quotas reset on the 1st of the month.