Email domain check.
Enter your domain and we read its public DNS records. They decide whether a stranger can send email that looks like yours, and whether your own email is trusted.
Free. No sign-up.
What it checks.
SPF
- One record, and only one
- What it tells other servers to do with senders it does not list
- The number of lookups it needs, which is capped at ten
DKIM
- Whether a signing key is published
- The names Microsoft 365, Google Workspace and the usual sending services use
DMARC
- A policy record, and only one
- Whether it rejects, quarantines or only watches
- Where the reports go
Mail servers
- Where email for the domain is delivered
- Whether delivery is made to insist on encryption
What it cannot tell you.
- It reads public DNS only. It does not send email, sign in to anything or touch your mail service.
- DKIM keys sit under a name your mail service chooses. We try the common ones, so a key we do not find may still exist.
- A clean result here does not mean a mailbox is safe. Passwords, multi-factor authentication and forwarding rules are a separate matter.
Further reading
Related
- Best Practices The fundamentals done properly: sign-in security, patching, access control and policy.
- Security Awareness Practical training and phishing simulations that teach staff to spot the trick.
- Identity & Access Management One sign-in for each person, the access their role needs and nothing more, removed the day they leave.
- Website health check Speed, security and SEO basics for any web page, checked in a few seconds.
- Website security headers check The instructions a website gives browsers to protect its visitors, read and explained.
- Domain and certificate expiry check When the certificate runs out and when the domain is due for renewal, before either takes the site down.
- Essential Eight assessment Twenty-four statements, about five minutes, and an estimated maturity level for each strategy.
Tell us what needs sorting.
Book a call or send an email. We reply within one business day.