Skip to content

Free Tools/Email Security Checker

Could someone spoof email from your domain?

Enter your domain and we'll grade its email protection: DMARC, SPF, DKIM, and mail routing, decoded into plain English. This is the first thing scammers check before impersonating a business. It takes about five seconds.

Read-only: we look up your domain's public DNS records, the same ones every mail server reads. Nothing is changed and nothing is stored.

What this tool checks

DMARC: your anti-spoofing policy

DMARC is a public instruction on your domain that tells Gmail, Outlook, and every other mail service what to do with email that fails your authentication checks: let it through, send it to spam, or reject it outright. A policy of "reject" (or at least "quarantine") is what actually stops impersonation. A policy of "none" only watches and reports, it blocks nothing.

SPF: who's allowed to send for you

SPF is a list of the servers allowed to send email on your domain's behalf (your mail provider, invoicing tool, marketing platform, and so on). If it's missing, too loose, or broken, anyone's server can claim to be yours and many receivers will take its word for it.

DKIM: a tamper-proof signature

DKIM adds an invisible cryptographic signature to every message you send, proving it really came from your domain and wasn't altered in transit. It's switched on in your email platform and published in DNS. We look for keys under the selectors used by Microsoft 365, Google Workspace, and other popular services.

MX: where your mail goes

MX records tell the world which servers receive your email. We check that they exist and show you where they point, which also tells you (and attackers) who hosts your email.

Common questions

What is DMARC and why does it matter?

DMARC is a setting on your domain that tells the world's mail servers what to do with email that claims to be from you but fails authentication checks. Without it (or with it set to "none"), scammers can send convincing fakes from your exact address, and receiving servers have no instruction to block them. It also affects deliverability: Google and Microsoft now expect DMARC from businesses that send email.

Is this check safe to run on my domain?

Yes. The tool only reads public DNS records, the same information any mail server looks up every time someone emails you. It makes no changes, sends no email, and touches nothing inside your systems.

My domain got a bad grade. How hard is this to fix?

Usually not hard, but the details matter. SPF and DMARC records are single lines of DNS, and DKIM is switched on in your email platform (Microsoft 365, Google Workspace, and others). The care comes in rolling out DMARC gradually so real email from tools like your invoicing or marketing software doesn't get blocked. This is routine work for us, so if you'd rather not touch DNS, just ask.

Why didn't you find my DKIM keys?

DKIM keys are published under a name called a "selector" that varies by provider. We check the most common ones (Microsoft 365, Google Workspace, and popular mail services), but if your provider uses a custom selector, our check can miss it even though DKIM is working. Your DMARC reports are the reliable way to confirm.

Bad grade? We fix email security all the time.

SPF, DKIM, and a safely rolled-out DMARC policy are included when we manage your IT, or we can fix them as a one-off project. Either way, the first conversation is free.