Is your domain protected against email spoofing?
Enter your domain below for an instant, free check of your SPF, DKIM, DMARC, and other email security records — no signup required.
Takes about 10 seconds. Your report gets a shareable link you can revisit anytime.
Why this matters
Without proper email authentication, anyone can send messages that appear to come from your domain — a common tactic in phishing attacks against your own customers, partners, and employees.
Mail providers are also increasingly strict: domains without SPF, DKIM, and DMARC configured correctly are more likely to have their legitimate mail flagged as spam, or rejected outright.
What we check
SPF
Controls which servers are allowed to send mail for your domain.
DKIM
Cryptographically signs your outgoing mail so it can't be altered in transit.
DMARC
Tells mail providers what to do with messages that fail authentication.
MTA-STS
Forces incoming mail to travel over an encrypted, verified connection.
TLS-RPT
Reports failures in that encrypted connection, so problems don't go unnoticed.
DNSSEC
Cryptographically signs DNS records so they can't be spoofed in transit.
BIMI
Shows a verified brand logo next to authenticated mail in the inbox.
CAA
Restricts which certificate authorities may issue TLS certificates for this domain.
Found something that needs fixing?
Our Email Security service walks you through hardening your domain step by step.
See how we can help