Enter your company’s domain. In a few seconds you will see whether a fraudster can send an email that looks as if it came from your director or accountant — and exactly what to fix.
The accountant receives an email from the director’s address: “Urgent — pay this invoice today.” Without SPF, DKIM and DMARC the forged sender looks exactly like the real one.
Fraudsters send “new bank details” to your clients from your domain. The money goes to them — the damage to your reputation stays with you.
Since 2024 Gmail and Yahoo, and since 2025 Outlook, require SPF, DKIM and DMARC from bulk senders — and ordinary business mail without them is trusted less.
The rule for receiving servers: what to do with an email that failed SPF and DKIM — deliver it, send it to spam or reject it. This is what actually stops forgeries.
Which servers may send mail for your domain. Without it, any server can.
A digital signature on every outgoing email that proves it was not forged or altered.
Who receives your mail — Microsoft 365, Google Workspace or your own server. The fix instructions depend on it.
Mandatory encryption of incoming mail and reports about delivery problems — an extra layer for those who take security seriously.
Everything comes down to one grade and one plain answer: can your domain be forged or not.
We list every service that sends mail on your behalf: Microsoft 365, the website, CRM, newsletters, accounting software.
We configure SPF and DKIM and turn on DMARC in monitoring mode — no legitimate email is lost.
We read the DMARC reports, find forgotten senders and fix them.
We switch DMARC to “reject”: forged emails in your name are no longer delivered.
Yes, it is safe. We only read the public DNS records of the domain — the same data any mail server in the world sees. We do not connect to your servers or send any emails. For statistics we keep only the domain name and its grade, nothing about you as a visitor.
We look for the key under the most common names: Microsoft 365, Google Workspace, popular hosting and newsletter services. If your provider uses a different name, the key is simply not visible from outside. Leave a request and we will check it manually.
If you switch on “reject” straight away without preparation — yes: emails from a forgotten service (website, CRM, newsletters) may stop arriving. That is why we start in monitoring mode and move to full protection only after 2–4 weeks of reports.
DMARC carries the most weight (up to 40 points), then SPF (25) and DKIM (20); MX, MTA-STS and TLS-RPT add up to 15 more. If the domain can be forged, the grade cannot be higher than D, however well the other records are set up.
Yes. The records live in your domain’s DNS, not in the mail service, so the check works with any provider. The result includes instructions for your particular service.
Setting up SPF and DKIM takes 1–2 days; full DMARC protection takes 2–4 weeks including the monitoring period. The cost depends on how many services send mail for you — we will name it after a free consultation.
We will set up SPF, DKIM and DMARC without losing a single legitimate email — for Microsoft 365, Google Workspace or your own mail server.