Skip to content

Free tools · 100% in-browser

Tools for people who run
their own mail infrastructure.

Practical, no-signup tools for PowerMTA operators and deliverability work. Everything runs in your browser — nothing you enter is ever uploaded or stored.

These are free, no-signup tools for the everyday work of running a sending operation: generating authentication records and config, checking and validating DNS, diagnosing bounces and headers, planning warm-up and capacity, and confirming you meet the 2026 bulk-sender rules. Every one runs entirely in your browser — nothing you paste or type is uploaded or stored — and each maps to a real step in setting up and operating PowerMTA. The grid below is the full set; the guide under it groups them by when you’d reach for each.

Generate

SPF / DKIM / DMARC generator

Build all three records — with a real DKIM key generated in your browser and the matching PowerMTA domain-key line.

Open tool →
Generate

PowerMTA config generator

Assemble a hardened /etc/pmta/config: sources, virtual MTAs, IP pools, DKIM and domain policy. Copy or download.

Open tool →
Analyze

Email header analyzer

Parse raw headers: SPF/DKIM/DMARC results, key fields, and the full Received chain with per-hop delays.

Open tool →
Check

DMARC record checker

Look up or paste a DMARC record and get every tag explained, with a checklist of issues to fix.

Open tool →
Check

SPF record checker

Validate an SPF record and count its DNS lookups against the 10-lookup limit that causes PermError.

Open tool →
Check

DKIM record checker

Inspect a DKIM record and decode the public key to report its real type and bit length, flagging weak or revoked keys.

Open tool →
Plan

IP warm-up scheduler

Generate a day-by-day volume ramp to warm new sending IPs up to your target, with CSV export.

Open tool →
Decode

SMTP & bounce code lookup

Decode any SMTP reply or enhanced status code: hard vs soft bounce, likely cause and the fix.

Open tool →
Read

DMARC report reader

Turn a raw DMARC aggregate (RUA) XML report into a per-source summary with pass rate and failing senders.

Open tool →
Comply

List-Unsubscribe generator

Build the one-click List-Unsubscribe headers Gmail, Yahoo and Microsoft require from bulk senders in 2026.

Open tool →
Plan

CIDR / subnet calculator

Work out network, broadcast, masks and usable hosts for any IPv4 block — and list the IPs to assign to virtual MTAs.

Open tool →
Comply

Sender compliance checklist

Score your setup against the 2026 Gmail/Yahoo/Microsoft bulk-sender requirements, with a fix link for every gap.

Open tool →
Measure

Deliverability calculator

Turn send numbers into delivery, bounce, complaint, open and unsub rates — scored against the thresholds that matter.

Open tool →
Check

Reverse DNS / FCrDNS checker

Check a sending IP's PTR and confirm forward-confirmed reverse DNS — the check behind SMTP 5.7.25.

Open tool →
Check

MX record checker

Look up a domain's mail exchangers by priority, resolve each host, and flag missing, null or broken MX.

Open tool →
Convert

DKIM key converter

Convert a public or private key PEM, or a DKIM record, into the DNS record, host and PowerMTA domain-key line.

Open tool →
Check

DNS lookup

Query A, AAAA, MX, TXT, NS, CNAME, CAA and SOA records over DoH, with SPF/DKIM/DMARC highlighted in TXT.

Open tool →
Check

Email address validator

Bulk-check addresses for syntax, domain MX, and role-based or disposable flags — a pre-send list-hygiene pass.

Open tool →
Analyze

EML viewer

Parse a raw .eml: decoded headers, MIME tree, base64/quoted-printable bodies and attachments. HTML shown as source.

Open tool →
Fix

SPF flattener

Recursively resolve include/redirect/a/mx to raw ip4/ip6 for a zero-lookup SPF record that fixes PermError.

Open tool →
Plan

Sending throughput calculator

Estimate messages per hour/day and time-to-send from per-vMTA rate, IP count and a real-world efficiency factor.

Open tool →

A guide to the toolkit

Which tool, and when

Twenty-one tools is a lot to scan cold, so here they are grouped by the stage of work they belong to — roughly the order you meet them as you stand up and then run a server.

Generate & convert

When you’re building a setup, these produce the records and config you’ll publish. The SPF/DKIM/DMARC generator builds all three records with a real DKIM key made in your browser, the PowerMTA config generator assembles a hardened /etc/pmta/config from your IPs and domains, the DKIM key converter turns a key or record into the DNS line and the PowerMTA domain-key directive, and the List-Unsubscribe generator builds the one-click headers the major providers now require. Start here, then verify what you published.

Check & validate

Once records are live, these confirm they’re right — the step that catches the silent failures. The SPF checker counts your record’s DNS lookups against the ten-lookup limit that causes PermError, the DKIM checker decodes the public key to flag weak or revoked keys, and the DMARC checker explains every tag. Alongside them, DNS lookup, the MX checker, the reverse DNS / FCrDNS checker (the check behind SMTP 5.7.25) and the email address validator confirm the rest of the picture resolves before you send.

Diagnose

When something’s already gone wrong, these read the evidence. The email header analyzer parses raw headers into SPF/DKIM/DMARC results and a per-hop Received chain, the SMTP & bounce code lookup decodes any reply or status code into a likely cause and fix, the EML viewer opens a raw message down to its MIME tree, and the DMARC report reader turns an unreadable aggregate XML report into a per-source summary of who’s passing and who’s failing as you.

Plan & scale

Before you push volume, these size the move. The IP warm-up scheduler builds a day-by-day ramp to your target with CSV export, the throughput calculator estimates real messages per hour and day from your per-vMTA rate and IP count, the CIDR / subnet calculator works out the IPs to assign to virtual MTAs, and the deliverability calculator turns your send numbers into delivery, bounce, complaint and engagement rates scored against the thresholds that matter.

Comply & fix

Two tools target the rules and a common break. The sender compliance checklist scores your setup against the 2026 Gmail, Yahoo and Microsoft bulk-sender requirements with a fix link for every gap, and the SPF flattener resolves a too-many-lookups record down to raw ip4/ip6 to clear PermError. The List-Unsubscribe generator above belongs to this group too — one-click unsubscribe is now a requirement, not a nicety.

Why it all runs in your browser

Your records never leave the page

These tools work with sensitive material — DKIM private keys, raw message headers, real recipient addresses, your actual DNS records. So they run entirely client-side: the logic executes in your browser, and what you paste or type is never uploaded to a server or stored anywhere. The DNS-facing tools query public resolvers over DoH to read records, but the keys you generate and the messages you analyse stay on your machine. You can confirm it the honest way — open them with your network tab watching, and you’ll see nothing leave.

That matters most for the generators and analysers. A DKIM key pasted into a server-side “tool” is a private key handed to a stranger; a header dump can carry internal hostnames and addresses you’d rather not share. Doing the work in the browser removes that risk entirely, which is also why there’s no signup — there’s no account because there’s nothing to store.

Start here, by problem

A shortcut to the right tool

Mail is going to spam. Start with the header analyzer to see what’s passing, then the compliance checklist — and the emails-going-to-spam diagnostic walks the causes in order.

SPF is throwing PermError. Count the lookups with the SPF checker, then collapse the record with the SPF flattener; the PermError fix explains why.

You’re standing up a new server. Generate records with the SPF/DKIM/DMARC generator and a config with the config generator, then follow the install guide.

You’re bringing a new IP online. Build the ramp with the warm-up scheduler and size it with the throughput calculator.

A message bounced and you don’t know why. Paste the code into the SMTP & bounce code lookup for the cause and the fix.

You’re moving to DMARC enforcement. Read your aggregate reports with the DMARC report reader to find every sender before you tighten the policy.

You need to clean a list before sending. Run it through the email address validator for syntax, MX and role/disposable flags — a quick pre-send hygiene pass.

Free tools, paid product — and the line between

Where the tools stop and the product starts

These tools are genuinely free and genuinely complete for what they do. You can generate every record, validate every check, diagnose a bounce and plan a warm-up without paying for anything or creating an account — and plenty of people use them exactly that way, alongside a setup they run entirely themselves. Nothing here is a crippled demo of a paid feature; the generators produce real keys and real config, and the checkers give you the real answer.

What the tools don’t do is the doing. They’ll tell you the SPF record is over its lookup limit, but they won’t deploy the fixed one to your server; they’ll build a warm-up schedule, but they won’t run it day by day and adjust to each provider. That gap — from knowing to done — is where the Auto PMTA Configurator and the services live. Use the tools freely; reach for the product when you want the work done and operated rather than just diagnosed.

More than a PowerMTA toolkit

Useful whatever you send with

Most of these tools are engine-agnostic. SPF, DKIM, DMARC, reverse DNS, blacklists, bounce codes and list hygiene are the same whether you run PowerMTA, another self-hosted MTA, or a hosted platform — so the checkers, analysers, calculators and the compliance checklist are useful to any sender doing deliverability work, not exclusively PowerMTA operators. A handful are PowerMTA-flavoured by design: the config generator writes /etc/pmta/config, and the DKIM and record generators emit the matching domain-key directive alongside the DNS line.

The point is that you don’t have to be a customer, or even a PowerMTA user, to get real value here. If you send legitimate, opt-in mail and want to understand or improve where it lands, the toolkit is yours to use. And if you decide self-hosting is the right move after all, the same records and plans you built here carry straight into a real deployment.

Why they stay accurate

Built against the rules as they are now

Email’s rules move, and a tool that encodes last year’s thresholds quietly gives wrong answers. These are kept to the current state of play: the compliance checklist reflects the 2026 Gmail, Yahoo and Microsoft bulk-sender requirements, the List-Unsubscribe generator builds the one-click headers those providers now demand, the SPF tools enforce the real ten-lookup limit, and the reverse-DNS check mirrors what receivers actually test. They come out of running production PowerMTA infrastructure, so they encode the checks that matter in practice rather than the ones that merely look thorough.

That’s also why each tool tends to link to the deeper explanation behind it — a checker tells you what’s wrong, and the linked guide or fix tells you why and what to do next. The tools are the fast answer; the docs and fixes are the understanding underneath. Between them you should be able to get from a symptom to a resolved cause without leaving the site. And because the tools run in your browser rather than on a server we have to maintain, there is no usage cap, no queue and no reason to ration them — run any of them as often as the work demands.