Can they email as me?
Check whether your domain can be impersonated in email.
Free · No signup · Passive public checks only
This check only reads publicly published DNS records for the domain you enter — it does not access your mailbox, network or systems. We retain the result so you (or anyone you share the link with) can view it again; see the methodology page for what is tested and what each result can and cannot prove.
What a result looks like
Fictionalised example — not a real domain.
example.org — partially protected
- SPF: present, includes one sending provider
- DKIM: detected for one known selector
- DMARC: present, monitor policy (
p=none) — not yet enforcing
A check today, or ongoing visibility?
Configuration drifts — a DNS migration, an expired record, a new sending service nobody told you about. Monitoring re-checks a verified domain on a schedule and alerts you when something changes, with DMARC aggregate-report analytics on Pro and Agency.
How it works
Enter a domain. We read its public SPF, DKIM, DMARC and related DNS/TLS records — nothing else.
Plain-English findings, ranked by what to fix first, with raw evidence available for anyone who wants it.
Follow guided candidate DNS changes yourself, turn on monitoring, or bring in Suburban Secure.
Plans
Free for an anonymous check and one saved domain. Pro and Agency add monitoring, history and DMARC analytics.
FAQ
Does this prove my domain is secure? No — see the full FAQ.
Will this scan my mailbox or send any email? No — only public DNS records are read.
Follow the guided recommendations yourself, or:
Want ongoing visibility? Start monitoring.
Need someone to verify and implement it? Talk to Suburban Secure.
Can They Email As Me? is operated by Suburban Secure. Automated results are general guidance, not a complete mailbox or security audit.