Free tool · no sign-up
Free email security checker: SPF, DMARC and DKIM
Missing or weak SPF and DMARC records let anyone send email that appears to come from your company. Check your domain, then use the generator below to create a DMARC record.
DMARC record generator
Fill in the form and copy the record into your DNS (at your domain registrar, hosting panel or Cloudflare). Not sure? Keep the defaults: they monitor without affecting delivery.
How to roll out DMARC safely
- Monitor. Publish
p=nonewith a report address and read the reports for 2 to 4 weeks. - Fix senders. Make sure every service that sends as your domain (website, invoicing, newsletters) passes SPF or DKIM.
- Enforce. Move to
p=quarantine, thenp=rejectonce nothing legitimate fails.
Read more: our guide to DMARC and email spoofing.
Check everything at once
This tool looks at one area. The full website security scan also checks SSL, security headers, exposed files and outdated software, and gives you a score and a fix plan.
Free Security Watch
Keep an eye on your website, free
- A short re-scan summary by email once a month: your score, what changed and the top issues.
- A reminder 21 and 7 days before your SSL certificate expires.
- A reminder 30 days before your domain registration expires, when the registry publishes the date.
Up to 3 websites per email address. Unsubscribe with one click from any email. Need weekly scans, every finding and instant alerts? See Monitoring (AED 1,199 / year).
Questions about the Email Security Checker
What are SPF, DKIM and DMARC?
SPF lists the servers allowed to send email for your domain. DKIM adds a digital signature to each message. DMARC tells receiving mail services what to do when a message fails those checks, and where to send reports.
Which DMARC policy should I start with?
Start with p=none and a report address, so you can see who sends email as your domain without affecting delivery. When the reports show your real email passes, move to p=quarantine and then p=reject.
Why does the checker say DKIM was not found?
DKIM keys live under a "selector" name that each email provider chooses. We try common selectors only. If your provider uses a different one, DKIM may still be set up correctly; check your email provider's admin panel.
Do Gmail and Yahoo require DMARC?
Since February 2024 Gmail and Yahoo require bulk senders (around 5,000 messages a day to their users) to publish a DMARC record, alongside SPF and DKIM. Smaller senders are strongly encouraged to do the same.
Checking the security of
your website
- SSL certificateIs HTTPS valid, current and correctly set up?
- Security headersBrowser protections against clickjacking and script injection
- DNS and email securitySPF, DMARC and DKIM records that stop fake emails
- TechnologyVisible software and versions attackers look for
- ExposureBackup files, config files and admin pages left public
This usually takes 10 to 30 seconds. Please keep this page open.