(문서는 영어)
What it does
Email spoofing stays trivial until a domain publishes three DNS records that together prove who is allowed to send its mail. This tool builds those three records as ready-to-paste TXT values, one zone-file block per record:
- SPF (Sender Policy Framework, RFC 7208) — the TXT record at the zone apex listing the servers allowed to send mail for the domain. You edit the raw terms (mechanisms and qualifiers like
include:,ip4:,~all) one per line, exactly as they appear afterv=spf1. - DKIM (DomainKeys Identified Mail, RFC 6376) — the public key published at
<selector>._domainkey.<domain>. Set the selector, key type (k=), hashes (h=), test mode (t=y), and paste thebase64base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
public key (p=) your mail provider generates. - DMARC (RFC 7489) — the policy at
_dmarc.<domain>: policy (p=none / quarantine / reject), subdomain policy (sp=), report addresses (rua=/ruf=), sampling (pct=), and alignment modes (adkim=/aspf=relaxed or strict).
The sticky output panel shows all enabled records separated by comments, live as you type. A validation layer flags the classic publishing mistakes before they reach DNS: a missing DKIM selector, more than one SPF record, an SPF record with no ~all/-all/redirect= terminator, a DMARC record with no p= policy, and a domain that is not a fully-qualified name.
How to use it
- Pick a preset — Google Workspace, Microsoft 365, or Full enforcement — to start from a known-good shape, or paste your existing records into the import panel: SPF values (
v=spf1 …), DKIM values (v=DKIM1; k=…; p=…), and DMARC values (v=DMARC1; p=…) — bare values or full zone lines. Names like_dmarc.example.comorselector1._domainkey.example.comare read to fill the domain and selector fields. - Set the domain and DKIM selector, then fill each record’s fields. Each record has an on/off switch; disabled records drop out of the output.
- Copy or download
dns-records.txtand publish each block as a TXT record at your DNS provider.
Everything lives in the URL — share a link and the recipient sees your exact configuration.
Examples
A Google Workspace domain at monitor stage:
; SPF — TXT at example.com (the zone apex; often written "@")
example.com. IN TXT "v=spf1 include:_spf.google.com ~all"
; DKIM — TXT at google._domainkey.example.com
google._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A…"
; DMARC — TXT at _dmarc.example.com
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com; adkim=r; aspf=r"
What the validation layer catches as you edit:
- SPF terms without a terminal rule → “SPF needs ~all / -all or redirect=” — unmatched senders get a Neutral result.
- Two
v=spf1records pasted together → “Multiple SPF records” — receivers treat this as a permanent error and ignore SPF for the whole domain. - DMARC with no policy chosen → “DMARC p= policy missing”.
- Domain field holding
localhost→ “Not a fully-qualified domain”.
Good to know
- The p= key comes from your provider. DKIM keys are generated per domain by the sending service (Google Admin console, Microsoft Defender, Mailgun, …). The builder leaves
p=empty until you paste it — an emptyp=publishes as a revoked key, so fill it before going live. - Roll out DMARC in the standard order:
p=none+rua=→ study the aggregate reports →quarantine(optionallypct=below 100) →reject.p=rejectwithout working SPF/DKIM blocks your own mail. - One SPF record, one DKIM record per selector, one DMARC record — duplicates are permanent errors at receivers, not merge requests.
- Fully client-side. The builder never queries DNS and sends nothing anywhere; only the share URL leaves the page, and only when you copy it.
- Related tools: WHOIS /
RDAPRDAPThe modern JSON REST protocol for WHOIS-style registration data (domains, nameservers, entities), replacing the legacy plain-text WHOIS protocol.Learn more
Lookup (who owns the domain), Defang/Refang,HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Generator.