Free check · a few seconds

Can someone send an email
in your company’s name?

Enter your company’s domain. In a few seconds you will see whether a fraudster can send an email that looks as if it came from your director or accountant — and exactly what to fix.

@

We read only public DNS records — the same ones any mail server sees. Nothing is sent to your mailboxes.

Why it matters

One email can cost a company real money

A fake invoice “from the director”

The accountant receives an email from the director’s address: “Urgent — pay this invoice today.” Without SPF, DKIM and DMARC the forged sender looks exactly like the real one.

Your clients are deceived in your name

Fraudsters send “new bank details” to your clients from your domain. The money goes to them — the damage to your reputation stays with you.

Your real emails land in spam

Since 2024 Gmail and Yahoo, and since 2025 Outlook, require SPF, DKIM and DMARC from bulk senders — and ordinary business mail without them is trusted less.

What we check

Six records that decide whether your domain can be forged

DMARC

The rule for receiving servers: what to do with an email that failed SPF and DKIM — deliver it, send it to spam or reject it. This is what actually stops forgeries.

SPF

Which servers may send mail for your domain. Without it, any server can.

DKIM

A digital signature on every outgoing email that proves it was not forged or altered.

MX

Who receives your mail — Microsoft 365, Google Workspace or your own server. The fix instructions depend on it.

MTA-STS · TLS-RPT

Mandatory encryption of incoming mail and reports about delivery problems — an extra layer for those who take security seriously.

Grade A–F

Everything comes down to one grade and one plain answer: can your domain be forged or not.

How we fix it

Full protection without losing a single legitimate email

01

Audit — 1 day

We list every service that sends mail on your behalf: Microsoft 365, the website, CRM, newsletters, accounting software.

02

Safe setup

We configure SPF and DKIM and turn on DMARC in monitoring mode — no legitimate email is lost.

03

Reports — 2–4 weeks

We read the DMARC reports, find forgotten senders and fix them.

04

Full protection

We switch DMARC to “reject”: forged emails in your name are no longer delivered.

Questions

Frequently asked questions

Is the check safe? Do you store anything?

Yes, it is safe. We only read the public DNS records of the domain — the same data any mail server in the world sees. We do not connect to your servers or send any emails. For statistics we keep only the domain name and its grade, nothing about you as a visitor.

DKIM shows as not found, but we have it set up

We look for the key under the most common names: Microsoft 365, Google Workspace, popular hosting and newsletter services. If your provider uses a different name, the key is simply not visible from outside. Leave a request and we will check it manually.

Can turning on DMARC break our email?

If you switch on “reject” straight away without preparation — yes: emails from a forgotten service (website, CRM, newsletters) may stop arriving. That is why we start in monitoring mode and move to full protection only after 2–4 weeks of reports.

How is the grade calculated?

DMARC carries the most weight (up to 40 points), then SPF (25) and DKIM (20); MX, MTA-STS and TLS-RPT add up to 15 more. If the domain can be forged, the grade cannot be higher than D, however well the other records are set up.

We use Gmail or a hosting mailbox — does this apply to us?

Yes. The records live in your domain’s DNS, not in the mail service, so the check works with any provider. The result includes instructions for your particular service.

How long does the fix take and what does it cost?

Setting up SPF and DKIM takes 1–2 days; full DMARC protection takes 2–4 weeks including the monitoring period. The cost depends on how many services send mail for you — we will name it after a free consultation.

Close the gap before someone uses it

We will set up SPF, DKIM and DMARC without losing a single legitimate email — for Microsoft 365, Google Workspace or your own mail server.

Nicu — AI Consultant
NQData