Can someone send email pretending to be you?
Enter your domain. We read the three DNS records that decide the answer and explain each one in a sentence. No signup, and we log the domain and the time — nothing else.
Email me the full report with fix steps
The full report spells out exactly what to change, in the order worth doing it, with the records written out so your provider can paste them in. It is the same report we would hand a client.
This is the only step that asks for your details. We use them to send the report and to reply if you ask us something.
What the three records do
- SPF
- Lists which mail servers are allowed to send email as your domain.
- DKIM
- Signs your outgoing email so a receiver can confirm it really came from you and was not altered.
- DMARC
- Tells other mail servers what to do with email that fails those checks — ignore it, junk it, or reject it.
All three working together is what makes a spoofed email get rejected rather than delivered. Having one of them is common; having all three set correctly is not.
What this check does not do
It reads public DNS records, which is all it needs to answer the spoofing question. It does not log into anything, scan your network, or see inside your mailbox.
For some providers we cannot verify DKIM automatically, because the record name is specific to that provider. When that happens the result says so rather than guessing.
A full picture — admin accounts, backups, endpoints, who can see what — is the IT & Security Assessment.
Want us to fix it?
Most of what this check finds is an afternoon of DNS work, done carefully so nothing stops delivering while it changes. We reply to new inquiries within one business day.