Can someone send email
pretending to be you?
For most organizations the answer is yes, and nobody has ever told them. Three public DNS records decide whether a stranger can put your name on a message and have it land in someone's inbox looking genuine. This checks all three and explains what they mean in plain English.
We only read public DNS records. Nothing is sent to your domain, no email is sent, and nothing is stored about the result.
Impersonation is the attack, not the virus
The scams that actually cost people money rarely carry malware. They carry a name you trust. A message that appears to come from your church, your accountant, your bank or your employer does not need an attachment to work — it needs to be believed. Email authentication is the part of that you control: it is how a receiving server can tell your real mail from a forgery.
Most small organizations have some of it, badly configured, and no idea. That is not negligence — it is three obscure DNS records nobody ever explained. This tool exists to explain them.
- What this check does: reads three public DNS records for the domain you type.
- What it does not do: send anything to your domain, scan your network, touch your mail, or test anyone's password.
- You can run it on any domain — it only reads what is already public. It is the same information a scammer would look at before deciding whether impersonating you is easy.
Where should we send the results?
We will show your result on this page either way. If you would like the written version — what each finding means and the exact records to fix it — tell us where to send it.
We can fix it, or you can
Every finding above comes with the record you need to publish. Plenty of people take that to their IT provider and are done. If you would rather someone did it and then kept watching the inbox afterwards, that is what we do.