Type a domain. In under 3 seconds we pull live DNS records — SPF, DMARC and delivery policy — and grade your setup. No installation, no trackers, no signup.
Why this tool exists
“Before you buy another security tool, let's configure the ones you've already paid for.”
How the score is calculated
Your domain is wide open to spoofing. Anyone on the internet can send email pretending to be you.
SPF blocks some forgeries, but without DMARC the display name can still be spoofed in most clients.
Monitoring mode only. You see spoofing attempts in reports, but nothing is actually blocked.
Optimal configuration. Forged messages are quarantined or rejected before the recipient sees them.
What we check
TXT @ domain.comSender Policy Framework — the list of servers allowed to send as your domain. We parse the `all` mechanism (+ / ~ / -) and flag weak qualifiers.
TXT _dmarc.domain.comDomain-based Message Authentication — what happens when SPF/DKIM fail. We extract `p=` policy and verify that `rua=` reporting is in place.
TXT selector._domainkeyCryptographic message signature. DKIM requires knowing the selector, which is provider-specific — we surface it in the full report.
How it works
We resolve your TXT records directly from authoritative servers — no cached third-party data, no stale reports.
SPF `all` qualifier, DMARC `p=` policy and `rua=` reporting are parsed and scored against Google / Yahoo / Microsoft bulk-sender rules.
Each issue comes with the exact TXT record to paste into your DNS panel. Unlock the full report for IP reputation and DKIM.
Frequently asked
Yes. The scan, the score and the headline fixes are free and run on live DNS. The paid upgrade unlocks the full AI-generated report with DKIM, blacklist and reputation analysis.
The scan runs server-side and is not persisted. We only capture an email if you explicitly request the full report, so we can send it to you.
SPF authenticates the envelope sender, not the visible From: header. Without DMARC, any attacker can spoof your display name and most mail clients will show their message as if it came from you.
Yes. Since February 2024 bulk senders must publish DMARC. Our scoring aligns with the Google / Yahoo / Microsoft bulk-sender requirements, so a 100 here means you meet them.
We probe 20+ common DKIM selectors (Google, Microsoft 365, Mailgun, SendGrid, Zoho, Postmark, Amazon SES and more) and estimate key strength. Custom selectors are surfaced in the full report.
One senior specialist. Zero hand-holding. Results in weeks.