Tools
Check whether your email domain can be spoofed.
Enter your domain. The check reads the public DNS records that tell mail servers which services may send email for your domain, explains each result, and shows how to fix anything that is wrong.
Questions people ask
What are SPF, DKIM and DMARC?
SPF is the list of servers allowed to send mail as you. DKIM is a signature that proves a message was not changed on the way. DMARC tells receiving servers what to do when a message fails those checks, and sends you reports.
Why does this matter for a business?
Without these records, anyone can send invoices or password resets that look like they came from you. Google and Microsoft also expect them now, so mail from a domain without them is more likely to land in spam.
What does the check do?
It reads the public DNS records for your domain, the same ones every mail server reads before accepting your mail. We do not send any mail or change anything, and it usually takes a few seconds.
Why does it say DKIM could not be confirmed?
DKIM keys live under a name your mail provider picks, called a selector. We try the sixteen most common ones. If your provider uses a different name, we cannot see the key even when it is there. Your provider's DKIM page will tell you for sure.
Related pages
- Website health reportWhat your homepage tells a browser, a search engine, and an attacker.
- Cybersecurity and compliancePhishing protection, managed devices, tested backups and compliance.
- IT support and managed servicesComputers, servers, Wi-Fi, cloud, and a help desk your staff can call.
- ContactEmail and the contact form.
We can set these up for you
We set up SPF, DKIM and DMARC for your domain and monitor the DMARC reports for failures.