Free tool
Can criminals send email as your business?
Enter your domain and we will read the public DNS records that decide whether your email can be spoofed — SPF, DKIM, DMARC, MX, DNSSEC and CAA — then explain what each result means in plain English.
Domain and email security questions
- What does this domain health check actually test?
- It performs live public DNS lookups for your A, MX, SPF, DMARC, DKIM, DNSSEC (DS) and CAA records — the same records an attacker would read before attempting to impersonate your business by email.
- Why does DMARC matter for my business?
- Without an enforcing DMARC policy, anyone can send email that appears to come from your domain. This is the standard opening move in invoice fraud and payment redirection scams against Australian businesses.
- Is my data stored?
- We only read public DNS records for the domain you enter. Nothing is stored against you unless you choose to send the result to our engineers for a review.
- Can you fix the issues you find?
- Yes. Domain, DNS and email security hardening is delivered by our domains and security teams, including staged DMARC rollout from monitoring to full enforcement without breaking legitimate mail.
Related: Domains, DNS & email security · Cyber security · Essential Eight self-assessment
