How this check works

Scanner version 0.1.0-preview · methodology 2026-08-08 · last revised 2026-08-08.

Can They Email As Me? reads publicly published DNS, TLS and mail-transport records for a domain and explains what they mean for email impersonation risk. It cannot inspect your mailbox, administrator roles, multi-factor authentication, endpoint protection, backups, internal configuration or human processes — a clean result is not a claim that a domain or organisation is "secure."

Test contract
TestPlain-English output
Nameserver / SOAInformational resilience/configuration observations, with provider applicability.
SPF presence and syntaxPresent, absent, invalid, lookup-risk or review.
DKIMDetected, not detected, or unknown — never "absent" unless proven.
DMARCAbsent, monitor, partial enforcement or enforcement.
BIMI readinessEligible prerequisite, not eligible, detected or unknown; never implies logo issuance.
HTTPS/certificateHealthy, expiring, invalid or unavailable.
DNS (DNSSEC/CAA)Configured, missing or unknown.
MTA-STS/TLS-RPTConfigured, missing or invalid.
MX / mail providerHealthy resolution, configuration issue or informational.
SMTPPass, problem, unknown or platform-specific not-applicable.
Relay behaviourTested, not tested or not applicable; never infers an open relay from provider-expected behaviour.
Web headersInformational exposure only; CDN identity is not automatically a warning.
Reverse DNSEvaluated for mail-server IPs; proxied web/CDN IPs are not penalised for missing PTR.
BlocklistsListed, not listed, unknown or not checked; provider-blocked queries are unknown, not warnings.

Limitations

Correction and suppression

If a result is inaccurate, or you would like a domain's result suppressed, contact Suburban Secure and reference the result link. This page will link to a dedicated correction/suppression form in a future update.