Moletools

gmail.com — Email Configuration Report

A server-rendered snapshot of the domain's public email DNS configuration, with evidence and practical guidance for each check.

DKIM selectors are chosen by your mail provider and cannot be discovered reliably from DNS alone. Leave this blank to skip DKIM.

This tool queries public DNS only. It does not connect to your mail server or send email. Results are cached for up to 10 minutes.

Results for

gmail.com

Checked: 2026-07-29T18:47:21Z

Pass: 3 Warning: 2 Fail: 1 Info: 1

MX — receiving servers

Pass

MX servers are published and their hostnames resolve to IP addresses.

DNS evidence
  • 5 gmail-smtp-in.l.google.com (172.253.158.27, 2404:6800:4003:c00::1a)
  • 10 alt1.gmail-smtp-in.l.google.com (192.178.230.27, 2404:6800:400b:c01b::1a)
  • 20 alt2.gmail-smtp-in.l.google.com (173.194.43.26, 2607:f8b0:400e:c1e::1a)
  • 30 alt3.gmail-smtp-in.l.google.com (172.217.78.26, 2607:f8b0:4023:1c05::1a)
  • 40 alt4.gmail-smtp-in.l.google.com (142.250.101.26, 2607:f8b0:4023:c06::1b)

SPF — authorized senders

Warning

The SPF record has no all mechanism, leaving the default handling less explicit.

DNS evidence
  • v=spf1 redirect=_spf.google.com

DMARC — alignment policy

Warning

DMARC is monitoring only (p=none) and does not ask receivers to block failing mail.

DNS evidence
  • v=DMARC1; p=none; sp=quarantine; rua=mailto:mailauth-reports@google.com

DKIM — signing key

Fail

The selector exists but its public key is empty, which indicates a revoked key.

DNS evidence
  • v=DKIM1; k=rsa; p=

MTA-STS — enforced transport TLS

Pass

An MTA-STS version record with a policy ID is published. The HTTPS policy file must also be valid for full protection.

DNS evidence
  • v=STSv1; id=20190429T010101;

TLS-RPT — transport failure reports

Pass

A TLS reporting address is published, allowing transport encryption failures to be reported.

DNS evidence
  • v=TLSRPTv1;rua=mailto:sts-reports@google.com

BIMI — brand logo declaration

Info

BIMI is not published. It is optional and does not affect basic mail delivery.

DNS evidence

No matching DNS record was returned.

Frequently asked questions

What does this check test?
It reads public DNS records used for mail reception, sender authorization, domain alignment, transport security reporting, and brand indicators.
Why do I need to enter a DKIM selector?
A domain can have many selector names and DNS does not provide an index of them. Your email provider or a DKIM-Signature header shows the selector after s=.
Does a healthy report guarantee inbox delivery?
No. DNS configuration is only part of deliverability. Sender reputation, message content, complaint rates, list quality, and each mailbox provider's policy also matter.