Skip to content

Free tool · Public DNS only · Nothing stored

The question your insurer now asks: Can someone send email as your business?

Enter your domain. We read the same public records the world's mail servers read — SPF, DKIM, DMARC — and tell you, in plain English, whether an attacker can forge mail from your name. No signup, nothing sent, nothing stored.

You can paste a full email address too — we'll read the domain after the @.

What this reads

Five public records. One honest verdict.

These records are already public — any mail server on earth reads them before it decides whether to trust a message from your domain. We just read them back to you, and grade them.

The one that decides the verdict is DMARC. SPF only guards the hidden envelope address; DMARC is what tells receivers to actually reject a forged "From." A perfect SPF record with DMARC set to none still leaves you spoofable — and that is where most businesses sit.

SPF Which servers are allowed to send mail for your domain, and how strictly.
DMARC Whether receivers are told to reject or quarantine mail that fakes your name.
DKIM Whether your outgoing mail is cryptographically signed (common selectors).
MX Where your mail is delivered — which provider actually runs your email.
DNSSEC + CAA Whether your DNS is signed against tampering and cert issuance is fenced.

Nothing is stored

The lookups run from your browser against Cloudflare's public resolver. No signup, no logging, no email sent. We never see your domain.

What it can't see

DKIM uses a private "selector" name. We try the common ones; if yours is custom it won't show, so we never call DKIM "missing" — only "not found at the names we tried."

A snapshot, not an audit

This grades your DNS posture, not your inbox, your filtering, or your users. The full picture is the IT Health Check.

Straight answers

What does "can someone send email as my business" actually mean?

Without the right DNS records, an attacker can forge the "From" address on an email so it looks like it came from you or a coworker. That is how invoice-fraud and CEO-impersonation scams start. SPF, DKIM, and especially DMARC are the public DNS records that tell the world's mail servers to reject those forgeries.

Is my SPF record enough to stop spoofing?

No, and this is the most common misunderstanding. SPF only checks the hidden envelope address, not the "From" your recipient sees. A domain can have a perfect SPF record and still be fully spoofable. DMARC at "quarantine" or "reject" is what actually tells receivers to block a forged From. Most small businesses have SPF and a DMARC policy of "none" — which monitors but blocks nothing.

Does this tool store my domain or send me anything?

No. It reads public DNS records the same way any mail server does, straight from your browser using Cloudflare's public resolver. There is no signup, nothing is logged, and no email is sent. It is a read-only snapshot of records that are already public.

My cyber-insurance renewal asks about email authentication. Is this related?

Directly. Underwriters increasingly ask whether you enforce DMARC and MFA. A domain sitting at DMARC "none" is a common reason for a higher premium or a declined claim after a spoofing loss. This check answers the email half of that questionnaire in seconds.

Found gaps? Fixing them is a morning's work.

Getting from DMARC "none" to enforced "reject" — without breaking your legitimate mail — is exactly the kind of thing we do for managed clients. We'll fix your email authentication and keep it fixed.