What this check shows
TXT records store text associated with a DNS name. They are commonly used for email authentication policies, domain ownership verification and service configuration.
DNSRadar displays each returned TXT value separately, making it easier to compare long SPF or verification records without a compressed JSON response.
When to use it
- SPF and DMARC verification
- DKIM selector checks
- Google or Microsoft domain validation
- Detecting duplicate or stale TXT policies
How to read the result
- A domain can legitimately publish multiple TXT records, but multiple SPF records beginning with v=spf1 are invalid.
- DKIM records live below a selector such as selector1._domainkey.example.com, not normally at the root domain.
- DMARC is queried at _dmarc.example.com and should contain a single policy beginning with v=DMARC1.
Command examples
Use these dig commands when you need to compare DNSRadar with a terminal check or collect evidence for a DNS provider.
dig example.com TXT +short
dig _dmarc.example.com TXT +short
dig selector1._domainkey.example.com TXT +shortTroubleshooting focus
Use this page for SPF, DKIM, DMARC, domain verification tokens and service configuration records. TXT lookups are especially sensitive to exact hostnames, because SPF usually lives at the domain root, DMARC at _dmarc, and DKIM below a selector.
Practical examples
- Check example.com TXT for SPF and verify that only one v=spf1 policy is published.
- Check _dmarc.example.com TXT before moving from monitoring to quarantine or reject.
- Check selector1._domainkey.example.com TXT when a mail provider says DKIM is missing.
- Compare verification tokens globally after moving DNS providers.
Common mistakes
Publishing more than one SPF policy
Multiple TXT records are allowed, but multiple v=spf1 records make SPF invalid.
Checking DKIM at the wrong hostname
DKIM records use selector._domainkey.example.com, not normally the root domain.
Treating TXT wrapping as multiple policies
Long TXT records may be split into quoted strings inside one DNS record.
Forgetting TXT during nameserver migration
Email authentication and SaaS verification can break even if web records look correct.
Questions
Why is a TXT answer split into several strings?
DNS packets can split long TXT values into character strings. DNSRadar joins segments belonging to the same record.
Why does my root domain not show DKIM?
DKIM uses a selector-specific hostname. Query the complete selector._domainkey hostname.