Free · No signup · Instant
Can someone send email pretending to be your business?
Enter your domain. We read the public DNS records that mail servers use to decide whether a message claiming to be from you is genuine — and tell you exactly what is missing.
Reads public DNS records only. Nothing is sent, stored or shared.
We ran this check across 31 independent Ocala businesses. 81% of them could be impersonated — including every law firm in the sample.
Also free: check whether your website is configured securely.
Why this matters
The attack that does not need to hack you
Business email compromise costs American businesses more than ransomware does. It needs no malware and no breach — only a domain that never told the internet who is allowed to send on its behalf.
A fake invoice from you
Your customer receives an invoice with your name, your branding and different bank details. It passes their spam filter because nothing tells it not to.
A payment redirect
Someone in accounts receives a request from the owner's address to change a supplier's bank account. The address is real. The sender is not.
Your reputation, not theirs
The customer who was defrauded believes the email came from you — and in every visible respect, it did.
Questions
About this check
What is email spoofing?
Spoofing is sending email with your business name and address in the From line without any access to your systems. No hacking is involved — if your DNS records do not forbid it, anyone can do it. It is how fake invoices and payment-redirection requests reach your customers looking exactly like they came from you.
What are SPF, DKIM and DMARC?
They are three DNS records that work together. SPF lists which servers may send mail for your domain. DKIM cryptographically signs your outgoing mail. DMARC ties the two together and tells receiving servers what to do when a message fails — nothing, junk it, or reject it. DMARC is the one that actually stops impersonation, and it is the one most small businesses are missing.
Is this check safe to run?
Yes. It reads public DNS records — the same information every mail server on the internet already sees when it receives a message from you. Nothing is sent to your domain, no mail is generated, and nothing about your systems is exposed that was not already public.
Do you store my domain?
No. The check runs when you press the button and the result is returned to your browser. We do not keep the domain, email it to ourselves, or add you to a list.
I have SPF. Am I protected?
Not on its own. SPF validates the hidden envelope sender, not the From address your staff and customers actually see. Without DMARC set to quarantine or reject, a forged message can pass SPF checks on the attacker's own domain and still display your name in the inbox.
How hard is this to fix?
The changes themselves are small — a few DNS records. The care is in the sequence. Publishing a strict policy before you have confirmed every legitimate sender is authorised will stop your own invoices, newsletters and booking confirmations from being delivered. That is why it is done in stages with reports reviewed in between.
Want the rest of the picture?
Email is one exposure. The free assessment covers backups, Microsoft 365 settings, patching and what your network shows the internet — findings in writing, whether or not you hire us.