64TEQ Tools Email protection check

Email protection check · free, runs in your browser

Find out whether anyone can send email as your company.

Most invoice fraud starts with an email that looks like it came from a real company. Three public DNS records decide whether that works against your domain, and most businesses have at least one missing or misconfigured. This reads all three, and the newer ones, and tells you what to change first.

Email protection check

Could someone send email pretending to be you?

Type your domain and we read its public email records: SPF, DKIM, DMARC and the newer ones. You get a plain-English read of what is set, what is missing and what to fix first.

These records are public: every mail server reads them before accepting a message from you. The check looks them up through Cloudflare's public DNS service, so the domain you type goes to Cloudflare and nowhere else, and nothing is stored. It reads what is published, not what your mail actually does, so a gap here is real and a clean result is a good start rather than a certificate.

The part after the @ in your email address. If you type a subdomain we check its parent for DMARC as well, the way receiving servers do.

Each record, what it says and what to do about it appear here, worst first, with the mail provider we recognise from your MX records.

How it works

Four steps, no account.

Type the domain

The part after the @ in your email address. Subdomains are fine; the parent is checked for DMARC the way receiving servers do it.

We read the records

SPF, DKIM under the common selector names, DMARC, MTA-STS, TLS-RPT, BIMI and DNSSEC, looked up through Cloudflare's public DNS service from your browser. SPF is followed through its includes and the lookups counted against the limit of ten.

Read the verdict

Each record gets a status and a plain-English line: what it says, what that means for forged mail and what to do. Worst first, with an overall grade.

Fix it, or ask us to

The list is in the order that matters. Publishing DMARC and moving it to reject is usually the whole job; we do it with you in an afternoon.

Straight answers

Questions about this tool.

Where does the domain I type go?
To Cloudflare's public DNS service (1.1.1.1), which answers the same questions any mail server asks before accepting a message from you. It does not go to us, and nothing is stored. If that service is blocked on your network, Google's public DNS is tried instead.
Why can it not find my DKIM key?
DKIM keys live under a name (the selector) that the sender chooses, and there is no way to list them. The check tries the thirty most common, which covers Google Workspace, Microsoft 365 and the big marketing and ticketing platforms. If yours is unusual the key may still exist.
What is a good result?
SPF with a hard or soft fail and under ten lookups, a DKIM key found and DMARC at quarantine or reject with a reporting address. That stops forged mail from your exact domain. It does nothing about lookalike domains or a mailbox that has been taken over, which is what multi-factor sign-in is for.
We use Microsoft 365. Does that not handle this?
Microsoft 365 signs and checks mail, but the records live in your DNS, not theirs, and a new tenant starts with no DMARC at all. Ten minutes in the DNS console fixes it.
Will tightening DMARC stop our own email?
Only mail that is not signed or not listed in SPF, which is why you start at p=none with a reporting address, read the reports for a week or two and add the senders you had forgotten (the CRM, the payroll system, the newsletter tool) before moving to quarantine and then reject.

Take the result to a person.

This tool is part of our cloud, azure and microsoft licensing work. A specialist reads what you found and says what we would do next, and if the answer is nothing, we say that.

Message a specialist on WhatsApp Speak to a person · 0203 858 0264 Email michelle.nayee@64teq.com