DNS tool

TXT Record Checker - SPF, DKIM and DMARC

Check TXT records worldwide for SPF, DKIM, DMARC and domain verification, and compare long DNS text values across independent resolvers.

Record type

What this check shows

TXT records store text associated with a DNS name. They are commonly used for email authentication policies, domain ownership verification and service configuration.

DNSRadar displays each returned TXT value separately, making it easier to compare long SPF or verification records without a compressed JSON response.

When to use it

  • SPF and DMARC verification
  • DKIM selector checks
  • Google or Microsoft domain validation
  • Detecting duplicate or stale TXT policies

How to read the result

  • A domain can legitimately publish multiple TXT records, but multiple SPF records beginning with v=spf1 are invalid.
  • DKIM records live below a selector such as selector1._domainkey.example.com, not normally at the root domain.
  • DMARC is queried at _dmarc.example.com and should contain a single policy beginning with v=DMARC1.

Command examples

Use these dig commands when you need to compare DNSRadar with a terminal check or collect evidence for a DNS provider.

Terminal
dig example.com TXT +short
dig _dmarc.example.com TXT +short
dig selector1._domainkey.example.com TXT +short

Troubleshooting focus

Use this page for SPF, DKIM, DMARC, domain verification tokens and service configuration records. TXT lookups are especially sensitive to exact hostnames, because SPF usually lives at the domain root, DMARC at _dmarc, and DKIM below a selector.

Practical examples

  • Check example.com TXT for SPF and verify that only one v=spf1 policy is published.
  • Check _dmarc.example.com TXT before moving from monitoring to quarantine or reject.
  • Check selector1._domainkey.example.com TXT when a mail provider says DKIM is missing.
  • Compare verification tokens globally after moving DNS providers.

Common mistakes

Publishing more than one SPF policy

Multiple TXT records are allowed, but multiple v=spf1 records make SPF invalid.

Checking DKIM at the wrong hostname

DKIM records use selector._domainkey.example.com, not normally the root domain.

Treating TXT wrapping as multiple policies

Long TXT records may be split into quoted strings inside one DNS record.

Forgetting TXT during nameserver migration

Email authentication and SaaS verification can break even if web records look correct.

Questions

Why is a TXT answer split into several strings?

DNS packets can split long TXT values into character strings. DNSRadar joins segments belonging to the same record.

Why does my root domain not show DKIM?

DKIM uses a selector-specific hostname. Query the complete selector._domainkey hostname.

Related DNS tools