Free • Takes seconds

Could someone send email as your company?

Type your domain and we’ll read its public email records, then tell you in plain English what they mean for your business.

A domain, a work email address or your website address all work.

  • MX
  • SPF
  • DMARC
  • DKIM
  • MTA-STS
  • TLS-RPT

We read public DNS records only, the same ones mail servers read. Your browser looks them up through Cloudflare’s public DNS. We don’t store anything, and nothing is sent to us unless you ask for the full review.

What we check

Six public records that any mail server can read. Here’s what each one does for your business.

  1. Where your mail goes MX

    The service that receives your email. It tells us which records to look for next.

  2. Who may send as you SPF

    A list of the services allowed to send email as your domain.

  3. What happens to fakes DMARC

    Your instruction to every receiving server for email that claims to be you but fails these checks: deliver it, send it to spam, or refuse it.

  4. Signing DKIM

    A signature on the email you send, so receivers can tell it really came from you and wasn’t changed on the way.

  5. Encrypted delivery MTA-STS

    Optional. Lets you require that email sent to you travels encrypted.

  6. Delivery reports TLS-RPT

    Optional. Reports on email that couldn’t reach you securely.

What a public check can’t see

Whether your email is actually being signed, and how it handles lookalike domains and spoofed replies. The free review looks at those too, then we walk you through what we found.

The same fake, two endings

DMARC is the record that tells receiving servers what to do with email that claims to be from your domain but can’t prove it. Here’s the difference it makes.

Illustration Without enforcement

Frombilling@yourcompany.com

SubjectInvoice 4471: updated payment details

Nothing tells the receiving server to refuse it, so it can land in your client’s inbox looking like it came from you.

Illustration With DMARC set to reject

Frombilling@yourcompany.com

SubjectInvoice 4471: updated payment details

The receiving server reads your DMARC, sees the fake can’t prove it came from you, and refuses it before it reaches the inbox.

Simplified. Receiving servers also run their own filters, so what happens without enforcement varies from inbox to inbox.

Records are just one layer

DMARC deals with fakes that use your exact domain. Lookalike domains, like a capital I in place of an l, are a different trick. That’s where the advanced email filtering and security awareness training in our Fortify cybersecurity come in.

Get the full review, free
Call Free Consultation