Can your email be spoofed?
Enter a domain to check its SPF, DKIM and DMARC — the three DNS records that decide whether scammers can send email as you, and whether your own email lands in the inbox or the spam folder.
How this works & what it can't tell you
- Everything runs in your browser. Your domain is looked up directly against public DNS-over-HTTPS resolvers (Cloudflare and Google) — those queries go straight from your browser, not through this site, and nothing is stored or logged.
- We read public DNS only. SPF, DKIM and DMARC live in public DNS records. This tool reads them the same way a receiving mail server does. It sends no email and touches nothing you own.
- DKIM can't be fully enumerated. DKIM "selectors" aren't listed in DNS, so we probe the ~30 most common ones. If your provider uses a custom selector, a "not found" here doesn't prove you lack DKIM — the grade says so when that happens.
- This is an exposure check, not a certification. It shows where you're at risk and how to fix it. It does not certify compliance and can't guarantee inbox placement — deliverability also depends on your sending reputation and content.