Find out whether criminals can send email that looks like it comes from your domain, and exactly which DNS records fix it.
Only the domain name is sent. DNS records are public information and the check reveals nothing about you.
Email was designed without any way to prove who sent a message. Three DNS records were added later to close that gap. SPF lists which servers may send mail for your domain. DKIM adds a signature that proves a message really came from you and was not changed. DMARC ties them together and tells every receiving mail server what to do with messages that fail: deliver them anyway, send them to spam, or reject them.
When those records are missing or set to monitoring only, anyone can send email that appears to come from your domain. Your customers, suppliers and staff receive it looking exactly like the real thing. This check reads your domain's public DNS, grades each record, tells you plainly whether the domain can be spoofed, and gives the specific fix for anything that is wrong.
Invoice and payment fraud against small businesses often starts with a spoofed email. A message arrives from what looks like your address or your accountant's, telling a customer your bank details have changed. Without an enforcing DMARC policy, that message can land in the customer's inbox with nothing to mark it as fake.
Spoofing also damages your reputation with email providers. When criminals send spam or phishing as your domain, receivers learn to distrust it, and your genuine invoices and newsletters start going to spam.
Large providers now require this. Since February 2024, Gmail and Yahoo require bulk senders to authenticate with SPF and DKIM and to publish a DMARC record, and many organisations and government agencies expect DMARC at quarantine or reject from their suppliers.
The fix is usually a small number of DNS changes. Most email providers publish the exact SPF and DKIM values to add. The safe path to DMARC is to start at p=none with reporting, confirm all your legitimate senders pass, then move to quarantine and finally reject.
SPF is a list of servers allowed to send mail for your domain. DKIM is a digital signature proving a message came from your domain and was not changed. DMARC checks that the address people see matches a domain that passed SPF or DKIM, and tells receivers what to do when it does not. You need all three.
Yes. DMARC protects against other people sending as you, which has nothing to do with how much you send. Small businesses are frequent targets for invoice fraud precisely because their domains are often unprotected.
It means monitoring only. Receivers send you reports about mail using your domain, but they still deliver messages that fail. It is the right place to start, but it does not stop spoofing until you move to quarantine or reject.
Open an email sent from your domain, view its raw headers, and find the DKIM-Signature header. The value after s= is the selector. Your email provider's admin console also shows it where DKIM is set up.
Each include in SPF, and each include inside those, counts toward a limit of ten lookups. Adding many services such as a CRM, a newsletter tool and a helpdesk can go over. Remove services you no longer use, or consolidate senders, so the total is ten or fewer.
It stops phishing that uses your exact domain, which is the most convincing kind. It cannot stop lookalike domains that swap a letter or add a word, so staff and customers still need to check sender addresses carefully.