Skip to content

Free tool

Email Security Check

Find out how easy it would be for someone to send email pretending to be your company. Enter your domain for a free grade in about 10 seconds, then get the full report with fixes by email.

This is a public DNS check only. It does not access your email, accounts, or systems.

What we check

Spoofing protection

SPF, DKIM, and DMARC, the records that stop someone sending as you. Plus BIMI, if you want your logo in the inbox.

Mail delivery

MX, MTA-STS, and TLS-RPT, which control where your email goes and whether it travels encrypted.

Domain security

Nameservers, DNSSEC, and CAA, which keep your domain answering correctly and limit who can issue certificates for it.

Why it matters

What spoofing and impersonation actually look like

Email spoofing is when someone sends a message that appears to come from your domain without having access to your email at all. They don't need to hack you. If your domain isn't set up to prove which email is legitimate, they can simply put your address in the "from" line and hope the receiving server accepts it.

Here's what that tends to look like in practice:

  • A client receives an invoice from "your" accounting address with new bank details, and pays it.
  • A vendor gets a request from "your" owner to update payment information or send a wire.
  • Your employees receive a message from "your" IT or HR address asking them to log in somewhere or open an attachment.
  • Your real email starts landing in spam folders, because receiving servers can't tell your legitimate messages apart from fakes.

The damage usually doesn't land on you first. It lands on your clients, vendors, and staff, who trusted the message because it had your name on it. That's why email authentication is increasingly on cyber insurance questionnaires, and why major email providers like Google, Yahoo, and Microsoft now expect businesses that send email at volume to have it in place.

Read more: Email Spoofing Only Works When the Easy Things Aren't Done

In plain language

The three records that do most of the work

SPF

Sender Policy Framework

SPF lists the services allowed to send email for your domain. Receiving servers check that list when a message claims to be from you. Think of it as a guest list at the door.

DKIM

DomainKeys Identified Mail

DKIM adds a digital signature that receiving servers check against your domain. A match confirms that the message came from you and was not changed along the way. Think of it as a tamper-evident seal on an envelope.

DMARC

Domain-based Message Authentication, Reporting and Conformance

DMARC ties SPF and DKIM together and tells receiving servers what to do when a message fails those checks. It can also report who is sending email using your domain. Think of it as the instructions to security.

The three work as a set. SPF and DKIM prove which email is really yours, and DMARC makes sure the fakes get stopped. The real protection comes from all three being set up correctly, with DMARC set to enforce. The other checks (nameservers, DNSSEC, CAA, MTA-STS, TLS-RPT, and BIMI) harden the domain around them, so they count for a little of your grade.

What this check does and doesn't do

This tool reads your domain's public DNS records, the same information any mail server in the world can see. It doesn't access your email, accounts, or systems, and it doesn't send anything to your domain.

It also can't see everything. DKIM can only be checked on common settings, so a custom setup may not show up here even if it's working. And the controls that do most of the real protecting, like multifactor authentication, tested backups, and how accounts are managed, aren't visible from the outside at all. That's what the free IT Environment Review is for.

Common questions

Questions about the Email Security Check