Fix an email authentication error
Paste your domain for a graded report, or pick the error you are looking at. Not sure which one you have? Work through the decision tree.
By error
- SPF PermError: too many DNS lookups
Find out how many DNS lookups your SPF record really costs, and which include to drop.
- SPF softfail vs hardfail
See which qualifier your record ends in, and whether moving to -all is safe yet.
- DMARC fail
Find out which of the three DMARC failure modes applies to your domain.
- dkim=fail (body hash did not verify)
The signature and key are fine. Something edited the message in transit.
- dkim=fail (no key for signature)
The message was signed, but the public key was not published where receivers look.
- No DMARC record found
Publish a DMARC record the right way, and start getting reports before you enforce.
- WordPress emails going to spam
WordPress is not a mail provider. The usual cause is an unauthenticated sender, not a wrong record.
By provider
Fix this from ChatGPT or Claude
MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:
“Diagnose email deliverability for example.com and tell me, in priority order, what to fix.”
- Claude: Settings → Connectors → Add custom connector, then paste
https://mcp.mailvakt.com/mcp. - Cursor and other MCP clients: add the same address as an MCP server. Setup details.
Checks are free and need no account. Sign in only to collect DMARC reports for a domain.