Skip to the tool
OnPageKit

Email, DNS & marketing

Compose SPF records within the ten-lookup limit, publish a valid ads.txt, tag campaign links with UTM parameters and hide email addresses from scrapers.

These four tools sit at the edge of on-page SEO, where a site's reputation depends on small text records that other systems read: mail servers deciding whether your email is genuine, ad buyers deciding whether an impression is authorised, analytics deciding which campaign brought a visitor. Each one fails silently when it is wrong, which is the reason to check it on purpose.

The SPF record generator composes the TXT record that lists who may send mail for your domain and counts the ten-lookup budget as you go. Every include, a, mx and redirect costs a lookup, including the ones nested inside your providers' own records, and going over ten makes SPF fail for every message. Publish ~all while you are still finding senders you forgot — the invoicing tool, the recruitment platform — and move to -all once DMARC reports show nothing legitimate failing. SPF does not protect the visible From address on its own; DKIM and DMARC do that alongside it.

The ads.txt generator writes and validates the IAB file naming the ad systems authorised to sell your inventory. If you run AdSense or any programmatic advertising, a missing or malformed ads.txt lets buyers treat your impressions as unauthorised, and revenue falls without an error anywhere. Each line names the ad system's domain, your publisher ID and the relationship, DIRECT or RESELLER; when a partner sends you a line, paste exactly what they sent.

The UTM builder adds utm_source, utm_medium and utm_campaign to a link without breaking the query string or fragment it already has. Keep the values lower case and consistent, because GA4 counts Facebook and facebook as two sources, and never tag internal links: an inbound campaign parameter starts a new session and credits the conversion to your own banner. The email obfuscator encodes mailto links so simple harvesters miss them and scans HTML for addresses left in plain text. Treat it as a speed bump rather than a lock — any scraper that decodes entities or runs a headless browser still reads the address.