Can your email be spoofed?

Enter a domain to check its SPF, DKIM and DMARC — the three DNS records that decide whether scammers can send email as you, and whether your own email lands in the inbox or the spam folder.

A domain, email, or URL — e.g. acme.com, you@acme.com, or https://acme.com.

Try one:

How this works & what it can't tell you

  • Everything runs in your browser. Your domain is looked up directly against public DNS-over-HTTPS resolvers (Cloudflare and Google) — those queries go straight from your browser, not through this site, and nothing is stored or logged.
  • We read public DNS only. SPF, DKIM and DMARC live in public DNS records. This tool reads them the same way a receiving mail server does. It sends no email and touches nothing you own.
  • DKIM can't be fully enumerated. DKIM "selectors" aren't listed in DNS, so we probe the ~30 most common ones. If your provider uses a custom selector, a "not found" here doesn't prove you lack DKIM — the grade says so when that happens.
  • This is an exposure check, not a certification. It shows where you're at risk and how to fix it. It does not certify compliance and can't guarantee inbox placement — deliverability also depends on your sending reputation and content.