Can someone send email as your business?
Type your domain. The check reads its SPF, DKIM and DMARC records and tells you whether a fake invoice from your address would reach your customers.
What the check looks at
- SPF
- The list of servers allowed to send mail for your domain, how it ends (-all, ~all) and whether it stays within the limit of 10 DNS lookups.
- DKIM
- The public key that lets receivers verify the signature on your mail. Looked up under the names most mail services use.
- DMARC
- Your instruction to receiving servers: what to do with mail that fails the checks, and where to send reports.
- MX
- Where your domain receives mail, which usually also shows which mail provider you use.
Questions
Someone is sending emails from my address. Has my mailbox been hacked?
Not necessarily. The From field of an email can be faked without any access to your mailbox, the same way anyone can write any return address on an envelope. Look in your Sent folder: if the messages are not there, it is most likely spoofing. A DMARC policy of quarantine or reject stops most of it.
What is the difference between SPF, DKIM and DMARC?
SPF is the list of servers allowed to send mail for your domain. DKIM is a signature on each message that receivers can verify. DMARC ties both to the address people see in the From field and tells receivers what to do when a message fails: nothing, the spam folder, or reject.
What do p=none, p=quarantine and p=reject mean?
p=none only collects reports and delivers everything. p=quarantine sends mail that fails to spam. p=reject tells receivers to refuse it. Only the last two protect you; none is the safe first step while you check that your own mail passes.
Why was no DKIM found when my provider says it is set up?
Each mail service stores its DKIM key under a name it picks, called a selector, and those names cannot be listed from outside. This check tries the names most services use. To be sure, open a message you sent in Gmail, choose "Show original", and look for DKIM: PASS.
What does "too many DNS lookups" mean for SPF?
While reading your SPF record, a receiver may look up at most 10 other records, counting the ones inside each include. Past 10 the whole record counts as failed. It happens when services are added over the years; the fix is to remove the ones you no longer use.
Can I go straight to p=reject?
You can, but it is risky. If your invoicing tool or newsletter is not set up with SPF or DKIM, its mail will be rejected too. Start with p=none and a report address, read the reports for a few weeks, then move to quarantine and then reject.
Other free tools
- SSL certificate checkerWhen does the certificate expire, who issued it, and do browsers trust it?
- Security headers checkWhich protections does your homepage ask the browser for? Graded A to F.
- Cookies before consent checkDoes your site set cookies or load Google Analytics and Meta Pixel before anyone clicks accept?
The full scan runs 20+ checks in about 90 seconds.
Free, no account. You get a plain-language report and a brief for your developer.
Go to the full scan