Skip to content

Free tool

Can someone send email as if it comes from you?

Most business domains are trivially easy to spoof. Enter your domain and we check your public DNS settings (SPF, DMARC and DKIM), the same records mail servers use. You will see instantly whether your domain can be abused for fake email.

Why this matters

This is how CEO fraud starts

Invoice and urgent-payment scams often begin with a mail that looks exactly like it came from a familiar domain. Without DMARC, that is trivial to pull off.

Your name takes the hit

The fake mail goes to your customers and partners, but your company name is on it. The trust you built gets used against you.

The fix is free

You do not have to buy anything. It is about setting a few DNS records correctly. Knowing what is missing is the only real step.

How it works

1. You enter your domain

No account, no install. Just your domain name.

2. We read your public DNS

We fetch your SPF, DMARC and DKIM records, exactly the ones receiving mail servers check.

3. You see the result instantly

A clear verdict in plain language: can your domain be spoofed, and what is set correctly or wrong.

We only read public DNS records. No email is sent, nothing is stored, and your systems are not touched.

What the fix guide contains

  • Which of SPF, DMARC and DKIM are missing or set too weakly
  • The exact DNS records to add, in plain language
  • How to move DMARC safely from monitoring to enforcing (none → reject)
  • How to verify it actually works

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.