Truvo Free Tools
MX record lookup
MX records tell every mail server on the internet which hosts accept email for your domain, and in what order. This MX record security check lists them, shows whether you have more than one host, and names the SOC 2 and ISO 27001 controls that depend on them.
Ali Aleali, CISSP, CCSP
Co-Founder & Principal Consultant
Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure. These tools come out of that work.
Connect on LinkedInHow MX record lookup works
The MX record lookup is passive: it reads the domain's public MX records through DNS over HTTPS and never connects to your mail servers.
01
Query
You enter a domain. The tool asks a public DNS over HTTPS resolver for the domain's MX records, the same query any mail server makes before it delivers email to you. Nothing is written or changed.
02
Read
Each mail host is listed with its priority value. Lower numbers are tried first. The tool also shows whether the domain publishes more than one host or depends on a single mail server.
03
Map
The result names the controls it speaks to: SOC 2 CC6.6 and A1.2, and ISO 27001:2022 A.8.14 and A.8.20. A single host is a gap to explain to an auditor; redundant hosts are evidence.
Found a gap? We fix it for you.
Truvo's security engineers harden mail, DNS and TLS, and hand you the evidence an auditor asks for. Tell us the domain and we will scope the fix.
-
Redundant MX hosts
-
SPF and DKIM
-
DMARC enforcement
-
MTA-STS
-
Audit evidence
-
Fixed-price scope
MX lookup: frequently asked questions
An MX lookup returns the mail exchanger records a domain publishes in DNS: the hostname of each server that accepts email for the domain, plus a priority number. Sending servers try the lowest priority value first and fall back to the others. An MX record security check reads the same records and asks two more questions: does the domain depend on a single mail server, and which controls does the answer affect.
Truvo maps MX findings to SOC 2 CC6.6 (logical access measures against threats from outside the system boundary) and A1.2 (the availability criterion covering recovery infrastructure), and to ISO 27001:2022 Annex A controls A.8.14 (redundancy of information processing facilities) and A.8.20 (networks security). The mapping is advisory: it shows which control a finding gives evidence for or signals a gap against. It is not a substitute for an audit.
Yes. The lookup only queries public DNS, over DNS over HTTPS, for records your domain already publishes to the whole internet. Nothing connects to your mail servers and nothing is written or changed. Any mail server that delivers email to you performs the same query.
ISO 27001:2022 control A.8.14 asks for information processing facilities implemented with enough redundancy to meet availability requirements, and SOC 2 A1.2 asks for recovery infrastructure that meets availability objectives. Inbound email is one of those facilities. A domain that publishes a single MX host has a single point of failure to explain to an auditor. Two or more hosts, or a provider that publishes several, is evidence the requirement is met.
MX records say where email for your domain is delivered. SPF records say which servers are allowed to send email as your domain. DMARC records tell receiving servers what to do when a message fails SPF or DKIM checks, and where to send reports. All three live in DNS, and a mail security review reads all three. This page covers MX; the SPF checker and DMARC checker below cover the other two.
More free tools
Run the full domain scan or check the other email records. See all free tools.
Domain security scan
Scan any domain for SPF, DMARC, DNS, TLS, security headers and subdomains in one pass. Graded A to F, each finding mapped to the SOC 2 and ISO 27001 control it supports.
SPF record checker
Validate your SPF record, catch lookup-limit and syntax problems, and see whether spoofed mail can pass as you.
DMARC record checker
Check whether your DMARC record exists, whether the policy enforces or only monitors, and whether reporting is set up.