Prune SPF and DKIM against your own reports.
Your SPF record only ever grows, and nothing in DNS lists your DKIM selectors. Two checks go through 90 days of your DMARC reports and tell you which SPF senders and DKIM keys are still in use. Remove the rest without cutting off a sender that's alive.
Create your account Test an edit before you publish it
Read from your reports · A verdict per include and selector · Part of the paid plans
Which SPF senders are still sending
SPF stops at ten DNS lookups. The record that hits the limit has grown for years because pruning it felt risky. Sending routes gives every mechanism a verdict and the proof behind it.
A verdict per mechanism
Every include, ip4, ip6,
a and mx term gets keep, review or
remove. Keep means addresses behind it sent mail that passed in the last
90 days. Remove means nothing behind it sent anything.
The lookup count and which include to drop
The page counts your lookups against the limit of ten and names the include to drop first: the one that costs lookups and sent nothing in 90 days.
Proof behind every keep
The busiest addresses that matched each term, each one a link into your reports, so a keep verdict points at real senders you can name.
A review verdict explains itself
Silence is only evidence when the page could have seen the mail. A term it can't measure says so, with the reason: an include that resolves against names it doesn't fetch, a walk that stopped, reports that don't cover the window yet.
Which selectors still sign your mail
Nothing in DNS lists a domain's DKIM selectors. Signing keys builds the list from your reports and checks every key against live DNS.
Every selector, found from your reports
Every selector a receiver saw sign your mail in the last 90 days, plus the common names providers use, checked in DNS one by one.
Every key checked in DNS
The page names the selector that stopped resolving, the key published empty, and the RSA key under 2048 bits that should be rotated, with the provider that issued it.
Old selectors after a key rotation
Rotate keys and the old selector keeps its DNS record, unused. The page marks a selector as retired once your mail stops signing with it.
Fix now, before anything else
A selector your mail signs with today whose key is gone from DNS is the one finding that costs you delivery this week. It sits at the top, on its own.
Test the change, then publish it
Paste the record you're about to publish into the free SPF change pre-flight. It names every address range that would stop being authorised, the include each one came from, and where the lookup count lands. Once the record is pruned, hosted SPF keeps it that way: one include, with the senders managed from a list on the page.
Part of Pro and Team
DNS cleanup comes with the paid plans, beside the monitoring they're built on: the Monday digest, same-day alerts, and the sender evidence behind every verdict. Pro watches 5 domains for $19 a month and Team watches 25 for $79. Every paid feature is free for 14 days, no card.
Where to go next
Questions people ask first
Does this change my DNS?
No. Both views read and grade. You make the edit, in your own DNS or on the hosted SPF page, and the daily record history shows the change the next day.
How far back does it look?
90 days of your domain's reports. A sender that last sent mail 91 days ago reads as retired, so read the proof beside a remove verdict before you drop a quarterly sender.
What does review mean?
Silence under a term that this page can't measure: an include that resolves against names we don't fetch, a walk that stopped, reports that don't cover the window yet. Each review row names its reason, and that tells you whether to wait or to check by hand.
What counts as a weak DKIM key?
An RSA key under 2048 bits. Signing keys names the selector and the provider that issued it, so you know whose rotation instructions to follow.
Can it find selectors my reports never named?
It guesses the common names providers use and checks each in DNS. A private selector name that no report has mentioned stays invisible until a receiver names it, which is a limit of DNS rather than of this page.
What if I'm on the free plan?
The free plan reads your SPF and DKIM records daily and keeps every change. The verdicts are part of Pro and Team, free for 14 days.
What does it cost?
It's part of Pro and Team. Pro watches 5 domains for $19 a month and Team watches 25 for $79. Every paid feature is free for 14 days, and the trial needs no card.
Read the verdicts before you touch the record
Add the domain, let the reports arrive, and both checks fill in over the first weeks. The first Monday digest already names the sender to look at.
First domain free · 14 days of every paid feature · No card
- Keep, review or remove on every SPF mechanism
- The lookup count and the include to drop first
- Every DKIM selector, checked against live DNS
- Weak and empty keys named, with the issuer