Email Auth Validator
Validate SPF, DMARC, and DKIM email authentication records for a domain
Parameters
| name | in | type | required | description |
|---|---|---|---|---|
domain |
query | string | required | Without https:// |
Request
Send your key in the X-API-Key header. More languages and patterns live on the
code examples page.
curl -s "https://apixies.io/api/v1/email-auth?domain=google.com" \ -H "X-API-Key: YOUR_API_KEY"
Response
The result sits under data in the standard envelope. See the
response format guide for errors and status codes.
returns
- data.spf
- SPF result with found, valid, the raw record, parsed parts and issues.
- data.dmarc
- DMARC result in the same shape as spf.
- data.dkim
- DKIM keys found across common selectors, plus any issues.
- data.domain
- The domain that was checked.
{
"status": "success",
"http_code": 200,
"code": "SUCCESS",
"message": "Email authentication validation completed",
"data": {
"domain": "example.com",
"spf": {
"found": true,
"valid": true,
"record": "v=spf1 include:_spf.google.com ~all",
"parsed": [
{
"qualifier": "+",
"mechanism": "include:_spf.google.com"
},
{
"qualifier": "~",
"mechanism": "all"
}
],
"issues": []
},
"dmarc": {
"found": true,
"valid": true,
"record": "v=DMARC1; p=reject; rua=mailto:dmarc@example.com",
"parsed": {
"v": "DMARC1",
"p": "reject",
"rua": "mailto:dmarc@example.com"
},
"issues": []
},
"dkim": {
"found": true,
"records": [
{
"selector": "google",
"type": "TXT",
"record": "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu5...",
"parsed": {
"v": "DKIM1",
"k": "rsa",
"p": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu5..."
}
}
],
"selectors_checked": [
"default",
"google",
"selector1",
"selector2",
"k1",
"dkim",
"mail",
"s1"
],
"selectors_timed_out": [],
"issues": []
},
"validated_at": "2026-09-18T12:00:00+00:00"
}
}
Authentication and limits
This endpoint needs an API key. Use the sandbox ("try it" above) to test it without registering. See the authentication guide for details.
Standard rate limits apply to this endpoint.
Common use cases
Email deliverability auditing
Check that your domain's SPF, DKIM, and DMARC records are correctly configured to prevent emails from landing in spam folders.
Domain security assessment
Audit client domains for email authentication vulnerabilities. Identify missing records that could allow email spoofing attacks.
Automated compliance monitoring
Continuously monitor email authentication records across your organization's domains. Alert when records change or expire unexpectedly.
related endpoints
More documentation
Get a free API key
A temporary key takes one click and no signup. Register and you get 75 requests/day. Free tier is for development & small projects.