Can someone send email pretending to be you?

We check the public DNS records for your domain: SPF, DKIM, DMARC, MTA-STS, DNSSEC, and leftover subdomains. It is a plain public lookup only. No email address required.

Optional. Only if you already know the host name before ._domainkey

Public DNS only. We do not collect your email.

What this means

Email spoofing means someone sends mail that looks like it came from your domain, even though it did not. Attackers use it for phishing, invoice fraud, and wire scams that target your customers and vendors. Three DNS records work together to stop it: SPF says which servers may send for you, DKIM cryptographically signs your mail, and DMARC tells receiving servers what to do when a message fails those checks.

A missing or weak setup does not mean your mailbox is broken. It means anyone on the internet can put your name on a message and many receiving servers will accept it. Fixing this is usually a same-day change to your DNS settings once your legitimate mail sources are known.

Three next steps

  1. 1

    List every service that sends email for you. Microsoft 365, Google Workspace, billing systems, marketing tools, and any copier or scanner that emails documents all count.

  2. 2

    Publish or tighten SPF and DKIM. Include every legitimate sender and remove stale entries, then confirm DKIM signing is turned on for your mail platform.

  3. 3

    Enforce DMARC. Start at p=none to watch reports, move to quarantine once you are confident, then finish at p=reject so spoofed mail is blocked outright.

Want help fixing what the check found?

Raulston Consulting Service can review your results and correct your SPF, DKIM, and DMARC settings for you.

This page performs a DNS-only lookup of publicly available records. It is not a full email security audit and does not cover every third-party sender or internal mail flow. Raulston Consulting Service can help you fix SPF, DKIM, and DMARC properly for your environment.