EDICT
what your domain declares

Who is allowed to send as you?

An offline grader for the SPF, DMARC, DKIM and CAA records a domain publishes, including the SPF ten-lookup budget — and it resolves no DNS to do it.

Python 3.10+PyQt6 network never515 testsMIT

Why

A few short lines in your DNS decide who the world believes may send mail as you. Most domains publish them once, copy a line from a provider's help page, and never look again.

They age badly. An SPF record quietly runs out of its ten DNS lookups and stops working, a DMARC policy sits at p=none for years rejecting nothing, a DKIM key stays at 1024 bits.

What it draws. The lookup budget — the ten DNS lookups SPF is allowed, drawn as segments, each labelled with the mechanism that spent it, with the limit as a hard line and the overflow past it.
Edict reading two samples

The reader on two of its bundled samples.

What it checks

SignalWhat trips it
SPF ending+all, ?all, or a sound -all
SPF budgetthe ten-lookup limit, and how close you are
SPF recordsmore than one, which is a permanent error
DMARCp=none enforces nothing; pct below 100
Reportingno rua means no reports reach you
DKIMkey size read from the published p=
CAAwhether anyone may issue a certificate for you

The honest part

Edict reads the records you paste. It resolves no DNS and does not follow include: chains, so the lookup count is a floor rather than a total — and the interface says so rather than rounding it off.

Install

git clone https://github.com/at0m-b0mb/Edict-Email-Policy.git
cd Edict-Email-Policy
python3 -m pip install -r requirements.txt

python3 -m edict                      # the window
python3 -m edict samples/             # the command line
python3 -m pytest -q                   # 515 tests

The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.

One of seven readers