Skip to content

Free tool

Can someone send email as your company?

Most small business domains can be spoofed and nobody has told them. Enter a domain and see what the rest of the internet already knows about it.

Reads public DNS only. Nothing is sent to the domain, and nothing is stored.

Common questions

What does this actually check?
The public DNS records that decide whether someone can send mail as your domain: SPF, DKIM across the common selectors, DMARC and its policy strength, plus MTA-STS, TLS-RPT, CAA and DNSSEC. All of it is published information that anyone can read.
Is this safe to run on a domain I do not own?
Yes. It only reads public DNS, the same records every mail server on the internet reads before accepting a message. Nothing is sent to the domain and nothing is probed.
Do you store the domains people check?
No. The check runs, the answer comes back, and nothing is written down. If you want us involved you have to tell us so through the form.
It says DMARC is monitor-only. Is that bad?
It means the record exists but tells receiving servers to take no action, so forged mail from your domain is still delivered. It is by far the most common place organisations stop, usually because moving past it risks blocking legitimate mail and nobody wants to own that risk.