Check your domain's SPF, DKIM and DMARC in seconds. Plain-English verdicts, free, nothing stored.
Passive DNS lookups only. We check public records; nothing about you is stored.
Three DNS records decide whether criminals can send email that looks like it comes from your business: SPF (which servers may send as you), DKIM (a cryptographic signature on your mail) and DMARC (what receivers should do when checks fail). Most Australian small business domains are missing at least one, which makes invoice fraud and customer-targeted phishing far easier, and quietly hurts deliverability of your legitimate mail. This tool reads your public records and explains each verdict in plain English.
Fixing a failing record usually takes minutes in your DNS console; your email provider documents the exact values. If you would rather it just be handled, email authentication setup is part of our managed IT and Microsoft 365 work.
Three DNS records that together authenticate your email. SPF lists the servers allowed to send as your domain, DKIM adds a cryptographic signature to each message, and DMARC tells receiving servers what to do with mail that fails those checks, and sends you reports about it.
Two reasons. Criminals who can spoof your domain can send your customers invoices with changed bank details in your name. And receivers like Google and Microsoft increasingly send unauthenticated mail to spam, so weak records mean your legitimate quotes and invoices quietly stop arriving.
Usually minutes per record in your DNS console. SPF and DKIM values come straight from your email provider's setup guide; DMARC can start in monitoring mode (p=none) the same day. The order that works: SPF, then DKIM, then DMARC, then tighten the DMARC policy once reports look clean.
Possibly. We probe the common selector names used by Microsoft 365, Google Workspace and popular senders, but some providers use custom selectors we cannot guess. If your provider confirms DKIM is enabled, treat that result as a false alarm; if you have never set DKIM up, it is real.
It means your domain is hard to impersonate and your mail authenticates properly, which is the foundation. Full email security also involves multi-factor authentication on your mailboxes and phishing awareness; see our Essential Eight guide for the bigger picture.