About
Method, sources and what is not checked
How the checker asks, how it reads what comes back, which documents it was written against, and the things it does not do.
What this site is
ė.email reads the DNS records that decide how a domain's mail is received and how mail in its name is judged: MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI. It has eight pages: the checker for all seven records, a page each for SPF, DKIM, DMARC, MX, MTA-STS with TLS-RPT and BIMI, and this one. The name is written ė.email; in the ASCII form that the DNS uses it is xn--lea.email.
The method
- Two resolvers, every time. Each question is sent from your browser to Google Public DNS and to Cloudflare over DNS-over-HTTPS, in JSON. The two sets of records are compared after normalizing what is only notation: the quotes and the splitting of TXT strings, the case and the final dot of host names. Address records are the exception: on 2026-09-28 the two resolvers returned different addresses for the same mail host (smtp.google.com, for one), as load-balanced services do, so for A and AAAA the comparison is whether the name has an address at all.
- Disagreement is shown. When the two differ, both answers are printed side by side and the page says which one the reading follows. When one operator fails or does not answer within 8 seconds, the page names it. When both fail, the card says the record could not be read and concludes nothing.
- Records are selected as receivers select them. A TXT answer counts as an SPF, DMARC, MTA-STS, TLS-RPT or BIMI record only if it begins with that record's version tag; everything else at the name is discarded, and the page says when it discarded something.
- SPF is followed, with guards. Every
includeandredirectis fetched, to a depth of 10 levels and 40 records, and a record that points back into its own chain is reported as a loop. The lookups are counted in the order a receiver meets them, against the limit of 10. - DKIM keys are measured. The value of
p=is decoded from base64 and the length of the RSA modulus is read from the key's own structure. It is not estimated from the length of the text. - DMARC discovery follows RFC 9989. The record at the domain first, then the DNS Tree Walk.
- No score. Findings are marked in order, caution or problem, each with the rule it comes from. They are not added up.
What is not checked
- No mail server is contacted: not the hosts in MX, not their TLS, not their certificates.
- No file is fetched from the domain: not the MTA-STS policy, not the BIMI logo, not its certificate.
- No message is sent or received, so nothing here says whether a particular message passes SPF, DKIM or DMARC.
- SPF macros are counted and not expanded.
- The public suffix list of RFC 7489 is not used; a receiver that still follows that RFC may choose a different Organizational Domain for a name under an unusual suffix.
- DNSSEC validation is left to the two resolvers; the page does not show its state.
- Both resolvers answer from a cache, so a record changed a moment ago may still appear in its old form.
Privacy, as the code has it
- The domain you type is sent to dns.google and cloudflare-dns.com, and to no other host. Those requests carry no cookies and no referrer. They do carry the Origin header that a browser adds to every request a page makes to another site, so the two operators can see that a question came from a page of xn--lea.email.
- The domain is not added to the page address, not written to local storage or a cookie, and not sent to this site's server.
- If you type an email address, the part before the @ is removed in your browser before anything is sent.
- This site stores one thing in your browser: the edition you chose, paper or dark, under the name
labs_edition. - When the site's Google Analytics tag is switched on, it records page views and the fact that a check was run, with the name of the page. It is never given the domain.
- No email address is collected anywhere on this site, and the site sends no mail.
Sources
The pages cite 17 documents, twelve of them RFCs. Each was fetched and read on 2026-09-28 (UTC).
- RFC 7208 — Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1, April 2014. Sections 3, 4.5–4.7, 5, 6 and 10.1.1. Read 2026-09-28.
- RFC 6376 — DomainKeys Identified Mail (DKIM) Signatures, September 2011. Sections 3.1, 3.2 and 3.6. Read 2026-09-28.
- RFC 8301 — Cryptographic Algorithm and Key Usage Update to DomainKeys Identified Mail (DKIM), January 2018. Section 3: sha1 retired, RSA key sizes. Read 2026-09-28.
- RFC 8463 — A New Cryptographic Signature Method for DomainKeys Identified Mail (DKIM), September 2018. Ed25519 keys; the sample key of Appendix A.2 is in the unit tests. Read 2026-09-28.
- RFC 7489 — Domain-based Message Authentication, Reporting, and Conformance (DMARC), March 2015. Obsoleted by RFC 9989, 9990 and 9991. Read for pct, rf, ri and the public suffix list. Read 2026-09-28.
- RFC 9989 — Domain-Based Message Authentication, Reporting, and Conformance (DMARC), May 2026. Sections 4.4, 4.5, 4.7, 4.8, 4.10, 9.3 and Appendices A.6, B and C.5. Read 2026-09-28.
- RFC 9990 — DMARC Aggregate Reporting, May 2026. Section 4: verifying report addresses outside the domain. Read 2026-09-28.
- RFC 8461 — SMTP MTA Strict Transport Security (MTA-STS), September 2018. Sections 3 and 5. Read 2026-09-28.
- RFC 8460 — SMTP TLS Reporting, September 2018. Section 3. Read 2026-09-28.
- RFC 5321 — Simple Mail Transfer Protocol, October 2008. Section 5.1: locating the target host. Read 2026-09-28.
- RFC 7505 — A "Null MX" No Service Resource Record for Domains That Accept No Mail, June 2015. Sections 3 and 4. Read 2026-09-28.
- RFC 2181 — Clarifications to the DNS Specification, July 1997. Section 8 (time to live) and 10.3 (MX targets are not aliases). Read 2026-09-28.
- BIMI draft 14 — Brand Indicators for Message Identification (BIMI), draft-brand-indicators-for-message-identification-14, 1 May 2026. An Internet-Draft that expires on 2 November 2026: work in progress, not a standard. Sections 4.3, 4.4 and 7. Read 2026-09-28.
- Google Public DNS — JSON API for DNS over HTTPS (DoH). The first of the two resolvers the checker asks. Read 2026-09-28.
- Cloudflare — Using JSON — DNS over HTTPS. The second resolver; asked with the header Accept: application/dns-json. Read 2026-09-28.
- Google Workspace Admin Help — Set up DKIM. States that the default prefix selector is google. Read 2026-09-28.
- Microsoft Learn — Set up DKIM to sign mail from your Microsoft 365 domain. Names the two CNAME host names selector1._domainkey and selector2._domainkey. Read 2026-09-28.
Colors
The accent is violet, #6D28D9 on paper and #C4B5FD on the dark ground. The build measures it as text against every ground it can stand on and stops below 4.5 to 1; the lowest of the measurements is 6.81 to 1.
| Edition | Color | Ground | Contrast |
|---|---|---|---|
| paper | --accent #6D28D9 | paper #ffffff | 7.10:1 |
| paper | --accent #6D28D9 | tint #FAFAFA | 6.81:1 |
| paper | --accent #6D28D9 | card #ffffff | 7.10:1 |
| paper | --accent-ink #5B21B6 | paper #ffffff | 8.98:1 |
| paper | --accent-ink #5B21B6 | tint #FAFAFA | 8.61:1 |
| paper | --accent-ink #5B21B6 | card #ffffff | 8.98:1 |
| dark | --accent #C4B5FD | paper #0C1116 | 10.27:1 |
| dark | --accent #C4B5FD | tint #10161C | 9.86:1 |
| dark | --accent #C4B5FD | card #121920 | 9.59:1 |
| dark | --accent-ink #DDD6FE | paper #0C1116 | 13.66:1 |
| dark | --accent-ink #DDD6FE | tint #10161C | 13.11:1 |
| dark | --accent-ink #DDD6FE | card #121920 | 12.76:1 |
Who publishes it
ė.email is published by Luxury American Brands LLC. Write to labs@labs.llc.