Free tool - private by design
Can someone send email pretending to be you?
Type your company domain. In about ten seconds you will know whether a faked message claiming to come from your business would land in someone's inbox. This is the trick behind invoice fraud and the "quick favour from the boss" scam.
Run the email spoof test
Every finding above is fixable, and usually within a day. Our Business Email Done Right package configures SPF, DKIM, and DMARC in the correct order and verifies delivery end to end, for a fixed $247.
Your email authentication is in good shape, which puts you ahead of most small businesses. Email is one of nine things we check in a free 30-minute IT health check, alongside backups and device security.
This test runs in your browser and reads only public DNS records, the same ones every mail server already reads. Nothing is uploaded to us, nothing is stored, and no email is sent.
How it works
Three records decide whether a fake gets through
-
MX: who handles your mail.
Tells us where your email actually lives, such as Microsoft 365 or Google Workspace. Useful context for the other two.
-
SPF: who is allowed to send as you.
A public list of the servers permitted to send email using your domain. With no SPF record, a receiving system has nothing to compare a suspicious message against.
-
DMARC: what happens to a fake.
The instruction to receiving inboxes. This is the one that matters most and the one most small businesses are missing. Without a DMARC policy of reject, a message that fails the checks is usually delivered anyway.
Good to know
Questions about this test
Is my domain sent to your servers?
No. The lookup runs in your browser and goes straight to a public DNS resolver, exactly as any mail server resolves your records. We never receive, store, or log what you type. That is the same standard as our other tools, and it is the way we build for clients too.
My result says a fake would be delivered. How bad is that?
It means someone can send mail that appears to come from your domain and the receiving inbox has not been told to refuse it. That is the mechanism behind invoice fraud and the scam where an employee gets a message that looks exactly like it came from the owner. It is also one of the faster problems to fix.
Can I fix this myself?
Yes. These are DNS records you or your IT provider can publish. The care is in the order: a DMARC reject policy published before SPF and DKIM are correct will start blocking your own legitimate email. If you would rather have it done and verified, that is our Business Email package.
Does passing this mean we are safe from phishing?
No, and we will not pretend otherwise. This test covers people faking your domain. It does not stop lookalike domains, compromised mailboxes at a supplier, or an employee clicking a link. Those need filtering, multi-factor authentication, and training. Passing this test closes one common door, not all of them.
We build software that does not want your data.
This tool stores nothing because it does not need to. We take the same approach to the systems we run for Chicago businesses: collect the least, protect what is left, and explain it in plain English.