Could someone send email as your company?
Type your domain and we’ll read its public email records, then tell you in plain English what they mean for your business.
- MX
- SPF
- DMARC
- DKIM
- MTA-STS
- TLS-RPT
We read public DNS records only, the same ones mail servers read. Your browser looks them up through Cloudflare’s public DNS. We don’t store anything, and nothing is sent to us unless you ask for the full review.
What we check
Six public records that any mail server can read. Here’s what each one does for your business.
Results for
-
Where your mail goes MX
The service that receives your email. It tells us which records to look for next.
-
Who may send as you SPF
A list of the services allowed to send email as your domain.
-
What happens to fakes DMARC
Your instruction to every receiving server for email that claims to be you but fails these checks: deliver it, send it to spam, or refuse it.
-
Signing DKIM
A signature on the email you send, so receivers can tell it really came from you and wasn’t changed on the way.
-
Encrypted delivery MTA-STS
Optional. Lets you require that email sent to you travels encrypted.
-
Delivery reports TLS-RPT
Optional. Reports on email that couldn’t reach you securely.
What a public check can’t see
Whether your email is actually being signed, and how it handles lookalike domains and spoofed replies. The free review looks at those too, then we walk you through what we found.
The same fake, two endings
DMARC is the record that tells receiving servers what to do with email that claims to be from your domain but can’t prove it. Here’s the difference it makes.
Frombilling@yourcompany.com
SubjectInvoice 4471: updated payment details
Nothing tells the receiving server to refuse it, so it can land in your client’s inbox looking like it came from you.
Frombilling@yourcompany.com
SubjectInvoice 4471: updated payment details
The receiving server reads your DMARC, sees the fake can’t prove it came from you, and refuses it before it reaches the inbox.
Simplified. Receiving servers also run their own filters, so what happens without enforcement varies from inbox to inbox.
Records are just one layer
DMARC deals with fakes that use your exact domain. Lookalike domains, like a capital I in place of an l, are a different trick. That’s where the advanced email filtering and security awareness training in our Fortify cybersecurity come in.
Get the full review, free