Canopytech Resources
Menu

Free · instant · no sign-up

Can someone send email pretending to be you?

If your domain isn't set up correctly, anyone can send an invoice that appears to come from your business — to your own customers. The damage lands on your reputation, and you usually hear about it from the client who already paid. This checks the three records that stop it, and tells you exactly what to publish.

Your email domain — the part after the @. An email address or a web address works too.

This reads public DNS records only. It does not connect to your mail server, probe anything, or send a test message. The domain you type is sent to our server to perform the lookup, and is not stored — see the FAQ below.

The three records, in plain English

Email was designed without any way to prove who sent a message. These three records are the retrofit. They work as a set — the first two produce evidence, and the third is what makes anyone act on it.

SPF

A published list of the servers allowed to send email using your domain.

Without it: Receiving servers have no list to check a sender against.

DKIM

A cryptographic signature added to each message, proving it wasn't altered in transit.

Without it: A message can be modified after it leaves you and still look legitimate.

DMARC

The instruction that ties the other two together and tells receiving servers what to do when a message fails both.

Without it: SPF and DKIM produce a verdict that nobody is obliged to act on.

How the score is worked out

Points are awarded for what your domain actually publishes: an SPF record that isn't broken, a strict enough SPF policy, a DKIM signature, a DMARC record, an enforcing DMARC policy, reporting, and a policy that applies to all of your mail rather than a percentage of it.

One deliberate exception: if we can't detect DKIM, those points leave the calculation entirely rather than counting against you. DKIM selectors are chosen when your mail is set up and can't be listed from outside — we try 28 common ones, and plenty of providers use something else. Marking a domain down for that would report a problem that isn't there, which is the flaw in most free checkers.

Well protected

90–100

Partly protected

60–89

Exposed

30–59

Wide open

0–29

What this is

A read of the public DNS records that decide whether your domain can be impersonated, with a specific fix for each gap. The same records anyone in the world can look up — including whoever might want to send mail as you. It is genuinely useful on a supplier's domain too, before you accept payment instructions by email.

What this is not

It is not a scan. Nothing connects to your mail server, no port is probed and no test message is sent. It also cannot see lookalike domains — an attacker registering a name one character from yours and authenticating it perfectly is a different problem, and these records do nothing about it.

Email Spoofing Check FAQs

What does this actually check?

It reads three kinds of public DNS record for the domain you enter: SPF (which servers may send as you), DKIM (whether your mail is signed), and DMARC (what receiving servers should do when a message fails the first two). It also checks MX records to see whether the domain receives mail at all. Everything it reads is published DNS that anyone in the world can look up.

Does this send my domain anywhere?

Yes, and this tool is different from our other two in that respect, so we would rather be plain about it. A DNS lookup has to happen somewhere. The domain you type is sent to our own server, which performs the lookups and sends the answer back. We do not store it, we do not log it against you, and no lead is created — but it is not a browser-only tool, and we would not want the privacy note on our other tools to imply otherwise. We chose this over doing the lookup from your browser precisely so that your IP address and the domain you are curious about are not handed to a third-party DNS provider.

Is this a scan of my systems?

No. It reads public DNS records and nothing else. It does not connect to your mail server, probe any port, send a test message, or touch anything you own. The same information is available to anybody with a command line, which is rather the point — it is available to whoever might want to impersonate you, too.

It says DKIM was not found, but we definitely have it. Why?

DKIM keys are published under a selector chosen when your mail was set up, and there is no way to list a domain's selectors from outside. Any checker can only try common ones, so a miss means "not found under the names we tried", never "not configured". If your provider uses a custom or rotating selector we will not see it. SPF and DMARC have fixed locations, so those results are definitive.

Can I check a domain I don't own?

Technically yes, since this only reads public records — checking a supplier's domain before you accept payment instructions by email is a genuinely sensible thing to do. It tells you nothing private about them, only what they have chosen to publish.

We publish everything and still get spoofed. How?

SPF, DKIM and DMARC protect your exact domain. They do nothing about lookalike domains — an attacker registering a domain one character different from yours, or your name with a different ending, and sending perfectly authenticated mail from it. That is a separate problem, addressed by monitoring for lookalike registrations and by training people to check the address rather than the display name.

Want these records fixed properly?

Publishing SPF and DMARC takes minutes. Getting to an enforcing policy without breaking your own mail takes a few weeks of reading reports — we'll do it with you.

Request a Quote