All tools

Are you at risk to email spoofing?

A free 10-second check that shows whether scammers can easily forge emails that look like they come from your business.

What is email spoofing?

Email spoofing is when a fraudster sends a message that pretends to be from you or your company, but isn't. They can use your good name to trick your customers into paying the wrong bank account, handing over passwords, or sharing sensitive information — and because the email looks genuine, people often fall for it. It is one of the most common causes of business fraud today, and it damages trust in your brand even when no money changes hands.

The good news is there are two simple behind-the-scenes settings — called SPF and DMARC — that tell the rest of the internet which mail servers are genuinely allowed to send on your behalf. When they are set up properly, spoofed messages get blocked or quarantined before they ever reach your customers. When they are missing or misconfigured, scammers effectively have an open door.

SPF — the guest list

Think of SPF as the guest list for your domain. It names the specific mail servers allowed to send email using your name. If someone not on the list tries it, the email can be rejected.

DMARC — the bouncer

DMARC is the instruction that tells the receiving inbox what to do when a sender fails the checks — silently monitor it, send it to junk, or reject it outright. It can also send you reports so you can see who is pretending to be you.

This tool simply looks up your domain's public records and shows you, at a glance, whether that guest list and bouncer are in place and doing their job. Nothing is stored — it is the same check anyone on the internet can run on your domain.

Your domain name is resolved via public DNS only — nothing is sent to or stored on our servers.