Godwit AI Labs Talk to us

Home › Free tools › Email security check

Can someone send email as you?

Three public records decide whether a forged invoice in your company’s name reaches an inbox, and whether your own mail lands in spam. Check yours in about ten seconds.

  • Public records only
  • The check stores nothing
  • About ten seconds
WHAT IT LOOKS AT

Five records, plainly

All of them sit in your domain’s public DNS. Since 2024 the largest mailbox providers expect the first three from anyone sending mail in volume, and junk or reject mail from domains without them.

  1. SPF · who may send as youThe list of systems allowed to send email in your name. Without it, receivers cannot tell your mail from a forgery.
  2. DKIM · a signature on every messageProof that a message came from you and was not changed on the way.
  3. DMARC · what to do with forgeriesYour instruction for mail that claims to be you and fails the two above. This is the one that stops a fake invoice.
  4. MTA-STS · encryption, requiredMakes other servers deliver to you only over an encrypted connection.
  5. TLS-RPT · reports when it failsAsks those servers to tell you when encrypted delivery did not work.
QUESTIONS

Asked often

The questions people search for before they run the check.

How do I check my DMARC record?

Type your domain in the box above. The check reads the TXT record at _dmarc on your domain and says whether it exists, which policy it sets (none, quarantine or reject) and whether reports are going anywhere. You can also look it up yourself with nslookup -type=TXT _dmarc.yourcompany.com.

What does “SPF too many lookups” mean?

An SPF record may make at most ten DNS lookups when a receiver checks it, and every include for a mail or newsletter service uses some. Past ten, receivers treat SPF as failed, even for genuine mail. The fix is to remove services that no longer send for you, or replace some includes with the addresses they stand for.

Do I need DKIM if I already have SPF?

Yes. SPF breaks when mail is forwarded; a DKIM signature travels with the message. DMARC passes when either one passes and matches your domain, and the largest mailbox providers now expect both from anyone sending mail in volume.

What DMARC policy should I use?

Start with p=none and a reporting address, read the reports for a few weeks, fix any genuine service that fails, then move to p=quarantine and finally p=reject. Going straight to reject risks blocking your own invoices or newsletters.

Why are my emails going to spam?

The most common reason is a missing or misaligned SPF, DKIM or DMARC record, which this check covers. Sender reputation and the content of the mail matter too, and those need a look at how your mail actually flows.

Is it safe to check my domain here?

The check reads only records that are public for every domain on the internet, and running it stores nothing: the domain is looked up once and the answer comes back to the page. If you ask for the report, we keep your details and a one-line summary of the result (the domain and how many findings of each kind), and nothing else.

Rather we just fixed it?

A short engagement: we find every service that sends as you, publish the records, read the reports with you and take DMARC to enforcement. Part of a wider security posture review if you want one.