Free tool
Can someone send email as your business?
For most small businesses the answer is yes — and they have no idea. Sending an email that appears to come from your domain takes about a minute and no technical skill, unless you've published three specific DNS records that tell the world's mail servers to refuse it.
Enter your domain below and we'll tell you straight away whether you're protected, and exactly what's missing if you're not.
Your domain or your email address — either works. No sign-up, and we only read public DNS records.
Why this matters more than it sounds
The damage isn't usually to you — it's to the people who trust you. The common version runs like this: a supplier or a customer receives an invoice that appears to come from your address, with your name, your usual wording, and different bank details. They pay it. By the time anyone works out what happened, the money is gone and the relationship is badly damaged, and it never touched your systems at all.
Nothing was hacked in that story. Your password wasn't stolen and your computer wasn't compromised. Anyone can put whatever they like in the "From" line of an email — the protocol was designed in the 1980s and simply doesn't check. The only thing that stops it is a published instruction telling receiving mail servers to reject anything that isn't genuinely from you.
The three records, in plain English
- SPF — the guest list
- Lists which servers are allowed to send email for your domain. On its own it's weaker than it sounds, because it checks a hidden address rather than the one the recipient sees.
- DKIM — the wax seal
- Cryptographically signs each message, so a receiver can prove it genuinely came from you and wasn't altered on the way.
- DMARC — the instruction
- Ties the other two to the address people actually see, and tells receiving servers what to do when a message fails: ignore it, bin it, or refuse it outright. This is the one that does the real work, and it's the one most businesses either skip or leave on "monitor only" forever.
One warning before you change anything
Don't jump straight to the strictest setting. If you switch DMARC to p=reject before every legitimate sender is properly authenticated, you will start rejecting your own mail — your invoicing software, your booking system, your newsletter, anything that sends on your behalf. The correct order is to publish a monitoring policy first, read the reports until you're confident nothing legitimate is failing, and only then tighten it. That usually takes a couple of weeks and is the part people get wrong.
Our other free tools
The free SEO analysis checks why your website isn't showing up in Google, and the free IT audit covers website security, domain reputation, and backups. Both are free and neither needs an account.