1 Summary
At a glance
2 Findings
3 What this could not check
“Nothing to fix” means only that the checks above found nothing. It does not mean a domain or its mail is safe from attack. Guidance, not an audit or a certification; see the terms.
Home › Free tools › Email security check
Three public records decide whether a forged invoice in your company’s name reaches an inbox, and whether your own mail lands in spam. Check yours in about ten seconds.
1 Summary
2 Findings
3 What this could not check
“Nothing to fix” means only that the checks above found nothing. It does not mean a domain or its mail is safe from attack. Guidance, not an audit or a certification; see the terms.
All of them sit in your domain’s public DNS. Since 2024 the largest mailbox providers expect the first three from anyone sending mail in volume, and junk or reject mail from domains without them.
The questions people search for before they run the check.
Type your domain in the box above. The check reads the TXT record at _dmarc on your domain and says whether it exists, which policy it sets (none, quarantine or reject) and whether reports are going anywhere. You can also look it up yourself with nslookup -type=TXT _dmarc.yourcompany.com.
An SPF record may make at most ten DNS lookups when a receiver checks it, and every include for a mail or newsletter service uses some. Past ten, receivers treat SPF as failed, even for genuine mail. The fix is to remove services that no longer send for you, or replace some includes with the addresses they stand for.
Yes. SPF breaks when mail is forwarded; a DKIM signature travels with the message. DMARC passes when either one passes and matches your domain, and the largest mailbox providers now expect both from anyone sending mail in volume.
Start with p=none and a reporting address, read the reports for a few weeks, fix any genuine service that fails, then move to p=quarantine and finally p=reject. Going straight to reject risks blocking your own invoices or newsletters.
The most common reason is a missing or misaligned SPF, DKIM or DMARC record, which this check covers. Sender reputation and the content of the mail matter too, and those need a look at how your mail actually flows.
The check reads only records that are public for every domain on the internet, and running it stores nothing: the domain is looked up once and the answer comes back to the page. If you ask for the report, we keep your details and a one-line summary of the result (the domain and how many findings of each kind), and nothing else.
A short engagement: we find every service that sends as you, publish the records, read the reports with you and take DMARC to enforcement. Part of a wider security posture review if you want one.