Free · instant · no signup
Can someone forge email from your domain?
Enter a domain. We read its public SPF, DKIM and DMARC settings — the three records that decide whether an attacker can send mail that looks like it came from you — and give you a plain verdict.
Lists which servers may send mail for your domain. Missing or ending in +all means anyone can.
Cryptographically signs your mail so receivers can verify it wasn't forged in transit.
Ties SPF and DKIM to the visible From address and tells receivers to reject forgeries. This is the one that actually stops spoofing.
Why it matters
Spoofed email is how most business fraud starts
Business email compromise and vendor-impersonation fraud almost always begin with a forged From address. DMARC at enforcement (p=quarantine or p=reject) is the single control that stops mail claiming to be from your domain — and it's free to configure. In our study of 405 credit union domains, roughly a quarter could not stop a forged email from their own name.
Questions
Isn't SPF enough?+
No — SPF alone doesn't cover the visible From address. You need SPF and DKIM aligned under a DMARC policy set to quarantine or reject.
What does p=none mean?+
It monitors but enforces nothing — forged mail still gets delivered. Move to p=quarantine, then p=reject.
Will enforcing DMARC break our email?+
Only if a legitimate sender isn't authorized. That's why you start at p=none to see reports, fix your senders, then ramp to enforcement.
Explore
Keep going
Full Domain Security Check
The complete posture grade: email, DNS, TLS, headers and registrar hijack protection.
Research405 CU domains graded
A quarter of credit unions can't stop a forged email from their own name.
All toolsFree security tools
Calculators, checkers and assessments — no signup.
Spoofable? We'll close it — usually in days.
DMARC done right is a short, well-understood project. We configure SPF, DKIM and DMARC, ramp you safely to enforcement, and monitor the reports.