Back to home
Free check

Is spoofing your domain possible?

Check it right now, free and with no sign-up:

  1. Enter your domain
  2. CyberAzimut analyzes your SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI configurations
  3. See your score
  4. Act fast with our personalized recommendations

Email authentication is one of the external security measures Law 25 expects.

Learn more about SPF, DKIM and DMARC

What this check reads

Six public records decide whether a stranger can write in your domain’s name, and whether mail addressed to you travels encrypted. Anyone can read them, you included. Here is what each one does.

SPFSender Policy Framework

Lists the servers allowed to send email for your domain. Without it, any server can claim to be yours. Published without a strict close, it enumerates your legitimate senders without refusing anyone else.

DKIMDomainKeys Identified Mail

A cryptographic signature your sending provider adds to every message, verifiable with a public key you publish on your side. It establishes that the message really comes from your domain and was not altered in transit. The key is published under a selector, a name the provider chooses.

DMARCDomain-based Message Authentication, Reporting and Conformance

Tells receiving servers what to do with a message that fails SPF and DKIM: let it through, quarantine it, or reject it. It is the only one of the three that refuses anything. A domain whose policy enforces nothing stays spoofable, however good the rest is.

MTA-STSStrict Transport Security for SMTP

Requires the servers writing to you to use an encrypted connection and to check your certificate. Without it, transport encryption is negotiated in the clear and can be stripped by anyone sitting on the path.

TLS-RPTSMTP TLS Reporting

Reports back when an encrypted connection to your servers fails. It protects nothing on its own: it is what lets you see that MTA-STS is not working.

BIMIBrand Indicators for Message Identification

Shows your logo next to your messages in the inboxes that support it. It requires a DMARC policy that already enforces, so it comes last and never first.

What this page does not do
  • No email is sent, to you or to anyone. The page reads what your domain publishes, the same way any mail server does before writing to you.
  • There is no account to create, no card, and no address to hand over to get the result.
  • It does not read your inbox and does not measure the deliverability of your campaigns. It looks at what your domain publishes, not at what it sends.
  • It sees what a receiving server sees at this moment. A record published a few minutes ago may not have propagated everywhere yet.
  • It is a snapshot of email authentication, not a picture of your internet exposure.

Common questions

Does the check send an email to my domain?

No. It reads what your domain publishes publicly, which is what any mail server does before writing to you. No message is sent and no mailbox is touched.

Do I need an account or a credit card?

Neither. You enter a domain, you get the result. No address is asked of you to see it.

Why is my grade held down when almost everything is green?

Because DMARC is the only checked record that refuses anything. As long as your policy enforces nothing, a spoofed message goes through despite a flawless SPF and DKIM. So the letter stays below the score until the policy enforces.

My domain does not receive email. Why is there no grade?

With no MX record, the domain does not receive mail and email authentication does not apply to it: there is nothing to grade, and this is not a bad result. If you send email from another domain, check that one.

What does a withheld grade mean?

It means at least one record could not be read. A grade calculated without it would be wrong: an unread SPF record alone is worth a whole letter. We would rather tell you what we did not see. Run it again in a few minutes, these failures are almost always temporary.

Does this make me compliant with Québec's Law 25?

No, and nobody can state that on your behalf. Email authentication is one of the external security measures an organization is expected to maintain under Law 25, and this page shows you where you stand on that specific point. CyberAzimut is not a certification body.

How often should the check be run again?

After every change to a tool that sends in your name, and otherwise a few times a year. SPF has a limit of ten DNS lookups: past that, receiving servers treat the record as invalid and it covers nothing. You reach it by adding tools one at a time, with nothing to signal it.

The other half of the question: which names close to yours are already registered. Free typosquatting check