Free tool · no signup
Enter a domain for a straight answer: protected, partly protected, or spoofable, based on what receivers are told to do with mail that forges it, and what to change if the answer isn't good.
01 How spoofing works
Email lets any server write any From address. What stops a forgery reaching an inbox is the receiver checking it, and being told what to do when it fails.
There's the hidden envelope sender (the bounce address), which SPF checks, and the From address people see. A forger can pass SPF with their own domain while showing yours.
DMARC requires SPF or DKIM to pass for the domain in the visible From line, and tells receivers to quarantine or reject mail that doesn't.
If the policy sets sp=none, anyone can send as billing.yourdomain or any made-up subdomain, which look just as convincing in an inbox.
02 Questions
Something else? Write to us — a real person answers, usually the same day.
03 More free tools
Each tool answers one question about a domain's email. All free, no signup.
All free tools ▶Every DMARC tag explained, report destinations verified, and the next step toward p=reject.
Authentication→Unrolls every include and counts lookups against the 10-lookup limit, with a corrected record.
Authentication→Record, DMARC enforcement, SVG Tiny PS logo and VMC/CMC certificate, checked together.
Every domain you run in one inbox, from $3 a mailbox. 14 days free, no card.