A check of the message, not the DNS
Send us your actual campaign.
We will tell you what is technically wrong — like everyone else — what is legally exposed, like nobody else, and whose job each one is. DNS shows what you published. A message shows what you actually send.
The inbound address is not switched on yet. Rather than show you a box that silently does nothing, here is the door that works today: paste one whole message and the same engine reads it — the same findings, the same rules, the same result page.
Paste a whole messageWhat it reads
Everyone checks a message against authentication. Nobody checks one against consent.
DKIM alignment on the message you actually sent
The d= domain against the From domain, plus whatever the receiver recorded. DNS can tell you a key is published; only a real message can tell you it signed the right domain.
One-click unsubscribe, both headers
List-Unsubscribe and List-Unsubscribe-Post. One without the other does not satisfy RFC 8058, and one without the other is the single most common real failure.
A postal address in the body
CAN-SPAM requires one on commercial mail. An address that lives only inside an image is not one, because the text is all a filter ever reads.
Whether Apple has any text to summarise
Apple Mail writes its own preheader from the first live text. Image-only campaigns get summarised from the subject line, and alt text does not save you.
Open tracking, stated as a fact
Whether the message carries a pixel, then the French rule that is in force and the Italian one that starts on 29 October 2026 — conditional on where you send, never asserted as a verdict.
The subject line against the body it describes
Only what a single message can defend: an offer named in the subject that is nowhere in the text, or a manufactured Re: on a message that is not a reply.
Every finding names the dated rule it comes from and says whether it is your ESP's job, shared, or yours — with the one concrete first move. There is no score, no grade and no percentage, here or on the share card.
What we keep
The findings. Not the message.
We store the findings, the From domain, the verdict sentence and the two dates. We do not store the body, the subject, the recipient, the address you sent from, or the raw headers. The message is parsed in memory and dropped. The share link expires after 30 days, and the page tells you the date it goes.
Send a real campaign, not a test with customer data in it. We read the HTML for facts and never render it, follow no link in it and run nothing from it — but the honest advice is still to send the same message you send your list, not one addressed to a person.
Already have the headers?
Paste a whole message instead. It runs the same engine — paste the full source and you get the content and consent findings too, not only the authentication ones.
For what you have published rather than what you send, check a sending domain.