Principle Security Principle Security.

Free · instant · no signup

Can someone forge email from your domain?

Enter a domain. We read its public SPF, DKIM and DMARC settings — the three records that decide whether an attacker can send mail that looks like it came from you — and give you a plain verdict.

SPF

Lists which servers may send mail for your domain. Missing or ending in +all means anyone can.

DKIM

Cryptographically signs your mail so receivers can verify it wasn't forged in transit.

DMARC

Ties SPF and DKIM to the visible From address and tells receivers to reject forgeries. This is the one that actually stops spoofing.

Why it matters

Spoofed email is how most business fraud starts

Business email compromise and vendor-impersonation fraud almost always begin with a forged From address. DMARC at enforcement (p=quarantine or p=reject) is the single control that stops mail claiming to be from your domain — and it's free to configure. In our study of 405 credit union domains, roughly a quarter could not stop a forged email from their own name.

Questions

Isn't SPF enough?+

No — SPF alone doesn't cover the visible From address. You need SPF and DKIM aligned under a DMARC policy set to quarantine or reject.

What does p=none mean?+

It monitors but enforces nothing — forged mail still gets delivered. Move to p=quarantine, then p=reject.

Will enforcing DMARC break our email?+

Only if a legitimate sender isn't authorized. That's why you start at p=none to see reports, fix your senders, then ramp to enforcement.

Spoofable? We'll close it — usually in days.

DMARC done right is a short, well-understood project. We configure SPF, DKIM and DMARC, ramp you safely to enforcement, and monitor the reports.