Meser10 Email Auth Check
Meser10 Email Auth Check
Description
Mail sent from a WordPress site fails quietly. Order confirmations, password resets and form notifications are accepted by the sending server, and then filed as spam by the receiving one. The usual reason is that the domain never published the three DNS records that prove the mail is really yours.
This plugin reads those records and tells you what they say.
What it checks
- SPF – that exactly one record exists, that it does not exceed the limit of ten DNS lookups, and that it ends with a policy instead of allowing everyone.
- DKIM – whether a public key is published under any of the selector names that sending services commonly use.
- DMARC – that exactly one record exists, which policy it asks for, and whether anyone is actually receiving the aggregate reports.
- Sending address – whether WordPress sends from the site domain or from a different one, because alignment is judged on the domain in the From address.
- MX – whether the domain can receive mail at all, so you know if replies and reports will bounce.
Two of these are worth stating on their own, because they are the failures people miss. A second SPF record does not add a sender, it switches SPF off. A second DMARC record does the same to DMARC. Both look harmless in a DNS panel and both are found by this plugin.
Every finding comes with an explanation in ordinary words and the exact change to make.
No external service
Every lookup is a plain DNS query made by your own server through PHP. Nothing about your site, your domain or your records is sent to any third party, and the plugin has no account, no key and no upsell. Results are cached for one hour and can be refreshed from the page.
Where to find it
Tools, then Email Auth Check. You need the manage_options capability.
Installation
- Install and activate the plugin.
- Go to Tools, then Email Auth Check.
- Read the report and fix anything marked Fail first.
Your host must allow the PHP function dns_get_record. Most do. If yours does not, the page says so.
Faq
No. The plugin only reads. Every change has to be made in the DNS panel of whoever hosts your domain.
Probably both are right. A DKIM selector name cannot be discovered from DNS. The plugin asks for the selector names in common use, and if your service uses a different one, the key exists but is not listed. Check the DNS instructions of the service you send with. The list of selectors can be extended with the meser10_eac_dkim_selectors filter.
p=none is the correct place to start, and the warning is not a criticism of it. It means the policy is not yet doing anything, so the report is reminding you that the work is unfinished.
No. It reads DNS records and nothing else.
It checks the domain of the site you run it on, with any leading www removed. On multisite, run it on each site whose domain differs.
Reviews
Changelog
1.0.0
First release. SPF, DKIM, DMARC, sending address and MX checks, with explanations and a one hour cache.