Call Book a call

Can someone send email pretending to be you?

Enter your domain. We read the three DNS records that decide the answer and explain each one in a sentence. No signup, and we log the domain and the time — nothing else.

The part after the @ in your work email. Pasting a full address or a website URL is fine.

What the three records do

SPF
Lists which mail servers are allowed to send email as your domain.
DKIM
Signs your outgoing email so a receiver can confirm it really came from you and was not altered.
DMARC
Tells other mail servers what to do with email that fails those checks — ignore it, junk it, or reject it.

All three working together is what makes a spoofed email get rejected rather than delivered. Having one of them is common; having all three set correctly is not.

What this check does not do

It reads public DNS records, which is all it needs to answer the spoofing question. It does not log into anything, scan your network, or see inside your mailbox.

For some providers we cannot verify DKIM automatically, because the record name is specific to that provider. When that happens the result says so rather than guessing.

A full picture — admin accounts, backups, endpoints, who can see what — is the IT & Security Assessment.

Want us to fix it?

Most of what this check finds is an afternoon of DNS work, done carefully so nothing stops delivering while it changes. We reply to new inquiries within one business day.

Book a 20-minute call 647-969-6900

We reply to new inquiries within one business day.