Email spoofing test
Someone is sending email as your business.
Email carries no proof of who sent it. We read the four public records that decide whether a forged message from your address reaches the inbox — and hand you the one that stops it.
One second. Nothing is emailed, nothing is signed in to, nothing is changed.
Checking
Reading your domain
Your result
Rather not do it yourself?
We will publish all three records for you.
Everything above is yours to use — the records are public and every step is on this page. This is only for when you would rather not edit DNS yourself.
Written scope and a price in writing before anything is touched. Your records, your DNS, your control.
The fix
One record. Free, and yours in five minutes.
Spoofing is stopped by telling receiving servers what to do with a message that fails. That instruction is a single DNS entry, and publishing it changes nothing about your own mail.
Read this before you publish it
The rua= part asks every mail provider to send you a daily report, forever,
as machine-readable XML. Point it at an address you do not read every morning, or you will switch this
off within a week like most people do.
Step by step: stopping it
At whoever manages your domain — usually where you bought it, or whoever hosts your website.
_dmarc — with the underscore.Want zero risk on day one?
Publish it with p=none instead. That enforces nothing and changes no
delivery at all — it only starts the reports. Once a few weeks of those look clean, change the one
word to quarantine. Slower, and completely safe.
What happens next
“We fixed it. Why is it open again?”
Because DNS records are edited by people who are not thinking about email, during work that has nothing to do with email.
Nothing announces it
Your own mail keeps working perfectly, because your mail was never the thing the record protected. The only visible symptom is a forged message somebody else receives — which you find out about weeks later, if at all.
So a domain fixed in March can sit wide open from June onwards with nobody aware. The only defence is re-checking, and it takes a second.
We found this on our own estate: three domains fixed, and we still re-check them, because we have watched records vanish during a hosting change before.
Why it matters
They do not blame the forger.
Spoofing is not a technical curiosity. It is a way of taking money from people who trust you, using your name to do it.
How it actually plays out
A customer owes you money. They receive an email from your address — your signature, your wording, your usual tone — with updated bank details.
They pay. When it unwinds weeks later, the conversation is not about who forged the message. It is about why your business let it happen.
And the quiet cost, every day
Domains with no policy are filtered harder everywhere. Your real quotes and invoices are likelier to sit in spam, and nobody tells you their mail went missing — they just assume you never replied.
The same record that turns forgeries away is what tells the big providers you are a domain worth trusting.
What is spoofing
A false return address that the post still delivers.
Email was designed in an era when everyone on the network was trusted. Nothing in it checks that the From address belongs to the person sending.
Typing your address into that field is as easy as writing a false return address on an envelope. No password is needed, no account is broken into, nothing of yours is hacked.
What decides whether the forgery arrives is entirely separate: whether you have published records saying it should not. Without them, every receiving server makes its own guess — and the safe guess for them is to deliver.
The two things people confuse
This test is about the first. Changing your password does nothing to stop it, which is why it keeps happening to businesses who think they have already dealt with it.
What it reads
Four records, and one answer.
DMARC
The instruction: deliver a forgery, send it to spam, or refuse it. The only record with teeth.
SPF
Which servers may send as you — and whether anyone else is actually refused.
DKIM
Whether your genuine mail is signed, so it survives once you start enforcing.
MX
Whether the domain receives mail at all. A domain with none can still be forged from.
Whether anyone is watching
If reports are being collected, or the forgery passes with nobody informed.
Subdomains
A policy on the domain does not always cover mail sent from a subdomain.
Partial enforcement
A policy can be weakened to apply to only a share of messages. We say when it is.
What to change
The exact record to publish, and what it is safe to tighten to later.
See it working
Type a domain — and get a yes or a no.
Not a score out of a hundred. A number tells you nothing about what to change.
What you get back
One sentence in plain words, then the evidence underneath it, then the record that fixes it.
The sentence
“Yes — a forged email would still be delivered. A policy is published, but it is set to take no action.”
Every record shown exactly as published, with the command to check it yourself.
A real result
We tested fourteen of our own. Eleven were open.
Before publishing this we pointed it at every domain we own. It is not a flattering result, and that is rather the point — nobody checks, including the people who should.
| What we found | Domains |
|---|---|
| No policy at all — anyone could forge them | 11 |
| A policy published that enforces nothing | 2 |
| Actually protected | 0 |
How it goes from here
Four steps, and only one of them is ours.
Test
You type a domain. We answer in one sentence whether it can be forged. Seconds, free, no account.
Publish
You add one record at your own DNS host. Nothing about your delivery changes.
Read the reports
They name every server sending as you, including the ones you forgot and the ones you never authorised.
Tighten
When nothing legitimate is failing, move to reject. Now a forgery is refused rather than delivered.
Questions
Before you ask.
Has my email account been hacked?
Almost certainly not. Spoofing needs no password and no access to your mailbox — someone simply types your address into the From field of their own message. That is why changing your password does nothing to stop it, and why it keeps happening to people who think they have already fixed it.
Someone is already sending emails as us. Does this stop it?
It stops the forgeries from being delivered, which is what actually matters. You cannot prevent someone typing your address — but you can instruct every receiving server on earth to refuse the result. That instruction is the record on this page.
Will publishing this affect my own email?
Not if you start at p=none, which enforces nothing and only turns on reporting. Moving to quarantine sends failing mail to spam — safe once you have confirmed your own services pass. The risk only appears if you jump straight to reject without checking.
How long does it take?
Adding the record takes about five minutes and takes effect within the hour. Getting to full enforcement takes a few weeks, because that part waits on reading the reports rather than on any technical work.
We are a small business. Would anyone bother forging us?
Forgery is automated and untargeted — domains are tested in bulk precisely because it costs nothing. Being small makes you likelier to be unprotected, not less likely to be tried. On our own estate, eleven of fourteen domains were open.
Can I check a domain that is not mine?
Yes. Everything read here is public DNS, the same information any mail server uses. People routinely check a supplier or a customer before trusting an invoice that arrived by email.
Guardrails
We read. We never change.
This tool touches nothing. Everything it reports comes from public DNS, and every change is one you make yourself, at your own host, in your own time.
We ran it on ourselves
Fourteen domains. Eleven had nothing.
Before publishing this we pointed it at every domain we own. It is not a flattering result, and that is rather the point — nobody checks, including the people who should.
| What we found | Domains |
|---|---|
| No DMARC record at all — anyone could forge them | 11 |
DMARC published but p=none — enforcing nothing | 2 |
| Actually protected | 0 |
Find out in a second. Fix it in five minutes.
No sign-up, no mailbox access, no obligation. If it turns out you are already protected, we will tell you that too.
Check my domain