Check a domain’s email security

See whether public email-authentication settings make a domain easier to impersonate.

Free · No signup · Passive public checks only

What the check covers

  • SPF: which mail systems the domain authorises to send.
  • DKIM: signatures detected for common selectors, with honest limits where absence cannot be proven.
  • DMARC: whether aligned mail is monitored, quarantined or rejected.
  • Related signals: relevant DNS, mail transport, TLS and web-security configuration.

Private by default

The check reads public records only. It does not access a mailbox, send email or scan an internal network. Results use an unguessable link and are excluded from search engines. Read the methodology and limitations before acting on a finding.

Prefer an overview first? Learn how email spoofing, SPF, DKIM and DMARC fit together.

Need help implementing changes? Talk to Suburban Secure.