← Back to the checker

How the score works

The overall score is a weighted total of the SPF, DKIM and DMARC results, out of 100. Every number on this page is read straight from the implementation (packages/core/src/check.ts), so changing the scoring logic changes this page with it.

Weighting

ItemWeightHow it is scored
SPF35Zero if no record is published, or if a syntax error or similar puts it in “Action needed”. A “Review” result earns 60% of the weight.
DKIM25Zero if no usable key is found. A “Review” result — a revoked or undersized key, for example — earns 60% of the weight.
DMARC40The policy strength sets the base, which is then scaled by the pct tag. A syntax error or an unauthorised external report destination halves it again.
Total100

Multiplier per DMARC policy

PolicyMultiplierHow it is scored
p=reject100%Spoofed mail is rejected — the most effective setting
p=quarantine75%Spoofed mail is quarantined as junk
p=none45%Monitoring only; spoofed mail is still delivered

When the pct tag is below 100, the result is scaled by “0.5 + pct ÷ 100 × 0.5”. At pct=100 (the default) the multiplier is unchanged.

Overall verdict

Alongside the score, one of three verdicts is assigned.

VerdictCondition
Good80 or above, with both SPF and DMARC published
Review45 or above (including when SPF or DMARC is missing)
Action neededBelow 45

What this number is, and is not

The weighting is our own, chosen to reflect how well a domain’s authentication stops spoofed mail. It is not an industry standard and not a certification by any third party.

The DKIM score only covers the selectors that could be found. DNS offers no way to list selectors, so a zero does not necessarily mean DKIM is unconfigured.

The score reflects the DNS responses at the moment of the query. Change the records and the result changes with them.