An offline grader for the SPF, DMARC, DKIM and CAA records a domain publishes, including the SPF ten-lookup budget — and it resolves no DNS to do it.
A few short lines in your DNS decide who the world believes may send mail as you. Most domains publish them once, copy a line from a provider's help page, and never look again.
They age badly. An SPF record quietly runs out of its ten DNS lookups and stops working, a DMARC policy sits at p=none for years rejecting nothing, a DKIM key stays at 1024 bits.
The reader on two of its bundled samples.
| Signal | What trips it |
|---|---|
| SPF ending | +all, ?all, or a sound -all |
| SPF budget | the ten-lookup limit, and how close you are |
| SPF records | more than one, which is a permanent error |
| DMARC | p=none enforces nothing; pct below 100 |
| Reporting | no rua means no reports reach you |
| DKIM | key size read from the published p= |
| CAA | whether anyone may issue a certificate for you |
Edict reads the records you paste. It resolves no DNS and does not follow include: chains, so the lookup count is a floor rather than a total — and the interface says so rather than rounding it off.
git clone https://github.com/at0m-b0mb/Edict-Email-Policy.git
cd Edict-Email-Policy
python3 -m pip install -r requirements.txt
python3 -m edict # the window
python3 -m edict samples/ # the command line
python3 -m pytest -q # 515 tests
The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.