Skip to content
GET /api/v1/email-auth

Email Auth Validator

Validate SPF, DMARC, and DKIM email authentication records for a domain

Parameters

name in type required description
domain query string required Without https://

Request

Send your key in the X-API-Key header. More languages and patterns live on the code examples page.

curl -s "https://apixies.io/api/v1/email-auth?domain=google.com" \
  -H "X-API-Key: YOUR_API_KEY"

Response

The result sits under data in the standard envelope. See the response format guide for errors and status codes.

returns

data.spf
SPF result with found, valid, the raw record, parsed parts and issues.
data.dmarc
DMARC result in the same shape as spf.
data.dkim
DKIM keys found across common selectors, plus any issues.
data.domain
The domain that was checked.
example response 200
{
    "status": "success",
    "http_code": 200,
    "code": "SUCCESS",
    "message": "Email authentication validation completed",
    "data": {
        "domain": "example.com",
        "spf": {
            "found": true,
            "valid": true,
            "record": "v=spf1 include:_spf.google.com ~all",
            "parsed": [
                {
                    "qualifier": "+",
                    "mechanism": "include:_spf.google.com"
                },
                {
                    "qualifier": "~",
                    "mechanism": "all"
                }
            ],
            "issues": []
        },
        "dmarc": {
            "found": true,
            "valid": true,
            "record": "v=DMARC1; p=reject; rua=mailto:dmarc@example.com",
            "parsed": {
                "v": "DMARC1",
                "p": "reject",
                "rua": "mailto:dmarc@example.com"
            },
            "issues": []
        },
        "dkim": {
            "found": true,
            "records": [
                {
                    "selector": "google",
                    "type": "TXT",
                    "record": "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu5...",
                    "parsed": {
                        "v": "DKIM1",
                        "k": "rsa",
                        "p": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu5..."
                    }
                }
            ],
            "selectors_checked": [
                "default",
                "google",
                "selector1",
                "selector2",
                "k1",
                "dkim",
                "mail",
                "s1"
            ],
            "selectors_timed_out": [],
            "issues": []
        },
        "validated_at": "2026-09-18T12:00:00+00:00"
    }
}

Authentication and limits

This endpoint needs an API key. Use the sandbox ("try it" above) to test it without registering. See the authentication guide for details.

Standard rate limits apply to this endpoint.

Common use cases

Email deliverability auditing

Check that your domain's SPF, DKIM, and DMARC records are correctly configured to prevent emails from landing in spam folders.

Domain security assessment

Audit client domains for email authentication vulnerabilities. Identify missing records that could allow email spoofing attacks.

Automated compliance monitoring

Continuously monitor email authentication records across your organization's domains. Alert when records change or expire unexpectedly.

More documentation

Get a free API key

A temporary key takes one click and no signup. Register and you get 75 requests/day. Free tier is for development & small projects.

cookies

We use analytics cookies to see how the site gets used. Nothing loads until you accept. Privacy policy