Email security check
Check any domain's SPF, DKIM and DMARC in seconds. See whether it can be spoofed, get a grade, and copy the exact DNS records to fix it.
What it checks
DMARC
Tells receiving servers what to do with email that fails SPF and DKIM: deliver it, send it to spam, or reject it. It also sends you reports. This is the setting that actually stops spoofing.
SPF
Lists the servers allowed to send email for your domain, so receivers can spot mail from anywhere else.
DKIM
Adds a tamper-proof signature to your outgoing email, so receivers can confirm it really came from you and was not changed.
MTA-STS and TLS reporting
Make other servers use encryption when they deliver email to you, and report when that fails.
Questions
Is it safe to check any domain?
Yes. The check only reads public DNS records, the same ones every mail server reads. It does not send email or connect to your servers.
Why can't it find my DKIM key?
DKIM keys are published under a selector name that cannot be listed, so the check tries the common ones. If yours uses a custom name, your email provider's admin console shows it.
How long until a fix shows up?
Usually minutes to a few hours, depending on the record's time-to-live. Run the check again after you publish a change.
Does this stop lookalike domains?
No. SPF, DKIM and DMARC protect your exact domain. That pushes attackers to register lookalikes such as yourc0mpany.com instead, which is what Horde Watch finds.