Free business email tool
Can someone pretend to send email from your business?
Start with the public records for your business email domain. See what SPF and DMARC say, what still needs checking, and what to ask your provider.
Business Email Protection Check
Ready when you are.
What these records can tell you
SPF identifies permitted sending sources for an email envelope domain. DMARC connects the visible From domain to aligned SPF or DKIM and publishes a requested handling policy. Record presence alone does not prove a message will authenticate.
Example: a monitoring policy is a starting point
If a domain publishes v=DMARC1; p=none, it is requesting monitoring rather than quarantine or rejection based on DMARC failure. Ask who reviews reports and whether every legitimate sender is aligned before changing the policy.
Questions to take to your provider
- Do all our mail systems, invoices and marketing platforms authenticate and align?
- Who reviews DMARC reports and handles unknown sending sources?
- Are DKIM signatures working on real messages from each service?
- What is our tested plan for tightening policy without blocking legitimate mail?
This is a public-record check
It does not test DKIM selectors, live message headers, SPF includes or lookup limits, inherited DMARC policies, mailbox compromise, MFA or delivery. It cannot protect against lookalike domains or a compromised legitimate account. A lookup failure is reported as inconclusive.
For suspicious mailbox activity, use the Microsoft 365 Suspicious Sign-In Guide. For broader public exposure, explore the external Security Checkup.
References: SPF specification, DMARC specification, Google DNS API.
