Collapser — DNS check
MX, verification, SPF, DKIM and DMARC for any domain. Public DNS only, no sign-in, no Google connection.
Paste a domain. You get the five records Google Workspace depends on, what state each one is in, and where there is a gap, the record to publish. Nothing is stored.
01 / What DNS can't tell you
The rest lives in the Google Admin console and in Gmail's settings, and no DNS query can reach it. Four things this page will never know, no matter how clean the table above looks:
Google's MX looks identical either way. A domain pointing at Google tells you Google handles the mail. It does not tell you which organisation, or whose.
Publishing the key is not turning it on. The key sits in DNS looking correct either way, and this page cannot tell the difference. It is a checkbox in the Admin console, and it is the one people miss.
Aliases are a Workspace setting. They leave no trace in DNS at all, so a domain with fifty of them and a domain with none look exactly alike from here.
Send-as lives in each Gmail account, per user. Nothing about it is public. This is usually the gap between "the records are right" and "I still can't send from that address."
For the first two, and to generate a DKIM key: Admin console → Gmail → Authenticate email. For aliases: Admin console → Users. For send-as: Gmail → Settings → Accounts.