Check if your email is properly protected against spoofing and phishing. We'll test your SPF, DKIM, and DMARC records.
Scammers can send emails that look like they're from your domain, tricking your customers and damaging your reputation.
Gmail, Outlook, and other providers check these records. Missing them means your legitimate emails may not reach inboxes.
SPF, DKIM, and DMARC work together to verify email authenticity, preventing phishing attacks that target your customers.
SPF lists which mail servers may send for your domain, DKIM adds a cryptographic signature that proves a message was not altered, and DMARC ties the two together and tells receivers what to do when a message fails, plus where to send reports. You need all three for reliable protection.
Publish an SPF record, sign your mail with DKIM, then publish a DMARC record and move it from p=none to p=quarantine and finally p=reject. At p=reject, receivers refuse mail that fails authentication and alignment, which blocks most spoofing.
Missing or misaligned SPF, DKIM or DMARC is a common cause. Gmail, Yahoo and Microsoft check these records and may filter or reject mail that fails, especially from bulk senders. Fixing authentication and alignment usually improves inbox placement.
Start at p=none to monitor without affecting delivery, review the aggregate reports, then tighten to p=quarantine and p=reject once your legitimate sources pass. p=reject gives the strongest anti-spoofing protection.
MTA-STS tells sending servers to require TLS when delivering to your domain, preventing downgrade attacks on inbound mail. It is recommended for any domain that wants encrypted, tamper-resistant email delivery.
Yes — checking SPF, DKIM, DMARC, MX and SMTP TLS is free and needs no account. An account adds continuous monitoring and alerts when a record changes.
We're new and growing — your feedback helps us improve.