Collapser — DNS check

What your DNS actually says.

MX, verification, SPF, DKIM and DMARC for any domain. Public DNS only, no sign-in, no Google connection.

Up to 10 domains, comma separated. The URL is shareable.

Paste a domain. You get the five records Google Workspace depends on, what state each one is in, and where there is a gap, the record to publish. Nothing is stored.

This page reads one third of the truth.

The rest lives in the Google Admin console and in Gmail's settings, and no DNS query can reach it. Four things this page will never know, no matter how clean the table above looks:

Whether the domain is in your Workspace, or someone else's

Google's MX looks identical either way. A domain pointing at Google tells you Google handles the mail. It does not tell you which organisation, or whose.

Whether DKIM authentication was actually started

Publishing the key is not turning it on. The key sits in DNS looking correct either way, and this page cannot tell the difference. It is a checkbox in the Admin console, and it is the one people miss.

Whether any aliases exist

Aliases are a Workspace setting. They leave no trace in DNS at all, so a domain with fifty of them and a domain with none look exactly alike from here.

Whether send-as is configured

Send-as lives in each Gmail account, per user. Nothing about it is public. This is usually the gap between "the records are right" and "I still can't send from that address."

For the first two, and to generate a DKIM key: Admin console → Gmail → Authenticate email. For aliases: Admin console → Users. For send-as: Gmail → Settings → Accounts.