
See whether a domain is protected against email spoofing and DNS tampering, with plain-English fixes for anything missing.
Looks up SPF, DKIM, DMARC, DNSSEC, CAA and more, straight from your browser using a public DNS service. Nothing is stored.
Together they stop people sending email that pretends to come from your domain. SPF lists the servers allowed to send your mail, DKIM adds a cryptographic signature to each message, and DMARC tells receiving servers what to do with mail that fails those checks and sends you reports.
Start with p=none and a rua address to collect reports, fix any legitimate senders that fail, then move to p=quarantine and finally p=reject. Only quarantine and reject actually stop spoofed mail being delivered.
Yes, because unused domains are easy to spoof. Publish 'v=spf1 -all' as SPF, a DMARC record with p=reject, and a null MX record (0 .) to state the domain sends and receives no email.
DNSSEC signs your DNS records so resolvers can verify they haven't been forged or tampered with. You enable it at your DNS host and add the DS record it gives you at your domain registrar.