For most organizations the answer is yes, and nobody has ever told them. Three public DNS records decide whether a stranger can put your name on a message and have it land in someone's inbox looking genuine. This checks all three and explains what they mean in plain English.
We only read public DNS records. Nothing is sent to your domain, no email is sent, and nothing is stored about the result.
The scams that actually cost people money rarely carry malware. They carry a name you trust. A message that appears to come from your church, your accountant, your bank or your employer does not need an attachment to work — it needs to be believed. Email authentication is the part of that you control: it is how a receiving server can tell your real mail from a forgery.
Most small organizations have some of it, badly configured, and no idea. That is not negligence — it is three obscure DNS records nobody ever explained. This tool exists to explain them.
We will show your result on this page either way. If you would like the written version — what each finding means and the exact records to fix it — tell us where to send it.
Every finding above comes with the record you need to publish. Plenty of people take that to their IT provider and are done. If you would rather someone did it and then kept watching the inbox afterwards, that is what we do.