Can someone send email pretending to be your company?
If your domain has no SPF and DMARC, a scammer can email your customers in your name, and your own email risks the spam folder. Find out in seconds, free.
Genuinely free. No sign-up, no email, no limits, no cookies. We don't store the URL you analyse.
Loading the security check…
Why it matters more than it seems
Email, as it was designed, doesn't verify who the sender is: anyone can put any address in the «From» field. That's why scams exist where a customer gets a fake email from your company, perhaps with new bank details for a payment. SPF and DMARC are the answer: two public «signs», written in the domain's DNS, that tell mail servers worldwide who's allowed to send for you and what to do with those who aren't.
The other side of the coin is your email. A domain without these protections looks less trustworthy to spam filters, and your messages, like quotes, confirmations, and replies, are more likely to end up in the recipient's spam folder, where nobody reads them.
What this tool checks
We query your domain's DNS, the same thing every mail server does when it receives a message from you, and read two records: SPF, to see whether it exists and is configured protectively (it should «close» with «-all» or «~all», not «+all», which lets everyone through), and DMARC, to see whether it's present and how strict (from «none», observation only, to «reject», full refusal). We tell you what's missing and what to improve, in plain language.
What to do if something's missing
SPF and DMARC are added as TXT records from the panel where you manage your domain or email: it's configuration, not programming, and whoever runs your domain can do it quickly. The golden rule is to ease into DMARC: first observation only, then «quarantine», finally «reject», so you don't accidentally block legitimate email. Copy the report with one click and hand it to whoever manages your mail.
While you're here, also check your WordPress security and your site speed. It's all on the tools page.
Frequently asked questions
›What are SPF and DMARC?
They're two records published in your domain's DNS that stop anyone sending email pretending to be you. SPF is the public list of servers allowed to send for your domain; DMARC tells mail providers what to do when an email impersonates you but fails the checks. Together they're the basic defence against phishing in your company's name.
›Why does it matter for a small business?
Two concrete reasons. First: without these protections, a scammer can send emails that appear to come from your company to your customers or suppliers, a reputational and financial risk. Second: your own emails are more likely to land in spam, so quotes and messages don't get through.
›Does this tool read my email?
No, never. We only check public records in the domain's DNS (the same ones any mail server consults): we don't connect to your mailbox, don't send email, and store nothing. It's like reading a posted sign, not opening your mail.
›Do you check DKIM too?
No, and we say so openly. DKIM is the third protection, but it depends on a «selector» chosen during mail setup that isn't publicly discoverable from outside. We check SPF and DMARC, the two verifiable pillars; for DKIM, ask whoever manages your domain's email.
›The result is red. How do I fix it?
SPF and DMARC are added as TXT records from your domain's management panel (where you bought the domain, or at your host). It's configuration, not programming: whoever manages your domain or email can do it quickly. Copy the report and pass it on.