Golang tool to check SPF, DKIM, TLSA, and TLS settings for mailservers
Yes, I admit, this is 100% vibecoded, but it scratches an itch i've had for a while. Seems to work for my usecases at this time, but might add some more features in the future. Comments
mailcheck is a compact Go-based command-line tool designed to inspect SPF, DKIM, TLSA, and TLS configurations for mail servers. When given a host, it validates TLS SNI/name matching and TLSA lookups. To run SMTP tests, the tool directly connects to the target's port 25. It does not send or authenticate emails. TLS certificate validation is separate from the TLS handshake, allowing inspection of untrusted certificates alongside DANE records.
The tool defaults to TLS 1.2, so servers supporting only TLS 1.0/1.1 will fail the modern TLS check. By default, it uses the github.com/miekg/dns library for DNS queries, which includes EDNS0 and DNSSEC support. mailcheck reports SMTP/TLS stages separately, so failures do not impact later stages. The --debug flag prints additional SMTP/TLS diagnostics.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.