Free Tool · Email Security
Type your domain and find out in seconds whether a stranger could send email in your company’s name — and exactly what is missing if they could.
Every domain can publish a short set of instructions telling the world’s mail servers which computers are allowed to send email for it, and what to do with anything else. Most small businesses have never published them. Many more published them years ago and never switched them on, which looks identical from the outside and protects nothing.
Until those instructions are in place and turned up, anybody can put your business’s name in the From line of an invoice and it will arrive looking exactly as though you sent it.
The checker is just below
At a glance
Type your domain and this checker reads what you have published to the internet, then tells you in plain English whether a stranger could send email in your name — and what is missing if they could.
Just the domain — yourbusiness.co.uk. An email address or a full web address works too; we will take the domain out of it.
Locking a domain down properly takes an hour or two and it is permanent. I do this for a living — tell me what the checker said and I will tell you what it would take.
What this can and cannot tell you. It reports what your domain has published to the world, which is exactly what a receiving mail server looks at when it decides whether to trust a message. It cannot see inside your mail system, cannot confirm your mail is being signed correctly in practice, and cannot prove a signature is missing — only that it could not find one at the usual names. Treat it as a strong indication, not an audit.
Who wrote this
CISSP CEH Founder, Systems Secure
Twenty-five years as an IT architect in the oil and gas industry, designing multi-million pound systems for companies around the world, before going independent. These days the work is smaller and a good deal more useful: helping UK businesses get enterprise-grade security without an enterprise budget.
I built this checker because most business owners have no idea this is even a setting, let alone that theirs is switched off. It is invisible until somebody uses it against you, and by then the damage is done to a customer rather than to you — which is what makes it so easy to keep ignoring.
If it found something and you would rather not go poking about in your own DNS, pick up the phone — or get in touch whichever way suits you. It is usually an hour’s work and it does not need doing twice.
No obligation · No sales script · You keep the findings either way
Yes, and it is easier than most people expect. The name in the From line of an email is not verified by anything unless you tell the world to verify it. Anyone with a mail server, or a few pounds and an online sending service, can put your company's address there.
The records this checker looks at are the only thing standing in the way. They tell every receiving mail server which computers are allowed to send email for you, and what to do with anything else. Without them, the answer is simply "deliver it".
It means your policy is set to "p=none" — the setting that watches and reports but takes no action. Forgeries are counted, and then delivered anyway.
This is the most common result we see, and it is not carelessness. None is where you are supposed to start, so you can find out who sends email in your name before you start blocking anything. The mistake is stopping there. Most domains are set to none during setup and are still sitting there years later, protecting nothing while looking, on paper, as though the job was done.
Handled carelessly, yes it can — and you deserve a straight answer about that rather than a reassuring one. If you jump straight to "reject" before you know every system that sends email in your name, the ones you forgot will stop arriving. That usually means invoices from your accounting software, booking confirmations, your newsletter, anything your CRM sends on your behalf.
The safe route is the reason "none" exists in the first place: turn on reporting, read a few weeks of it, fix what turns up, then tighten in stages. It takes a little patience rather than a little luck.
No, and this is the most common misunderstanding of the lot. Microsoft and Google will send and receive your email perfectly happily without any of this being set correctly.
SPF usually gets added during setup, because email breaks without it. DKIM often has to be switched on deliberately and frequently never is. DMARC is almost never configured by default at all. Your provider secures its own systems. Telling the world what to do with mail claiming to be you is your job, on your own domain.
Quite possibly you do. A signing key can be published under any name the person who set up your mail chose, and this checker can only look under the sixteen most common ones.
Finding nothing there is genuinely inconclusive, which is why it is shown as a note rather than a warning. If you know your selector name you can confirm it in your DNS in a moment, or ask whoever runs your mail.
The changes themselves are a handful of text entries in your domain's DNS settings and take minutes to type. The work is not the typing. It is knowing what to put, in what order, and how fast to tighten — which systems send email in your name, whether your SPF record is already close to the limit it is allowed, and what the reports are telling you.
If you have someone who manages your DNS confidently, they can do this. If the phrase "your domain's DNS settings" made you uneasy, that is a fair sign it is worth handing over.
It means nobody can forge your domain from the outside, which is a real and permanent win. It does not mean your email is secure.
The most common serious attack on a small business is not a forged domain at all. It is a real mailbox that somebody has got into, sending real email from the real account. Every check on this page would pass, because nothing is being faked. That is a different problem with different defences: strong sign-in, multi-factor authentication, and people who know to confirm any change of bank details by phone.
If you want to check a particular message that has arrived, that is what the Email Header Checker is for.

Innovation
Fresh, creative solutions.


Excellence

Systems Secure® Limited·Registered in England and Wales, company no. 07295869 6 The Meadow, Copthorne, West Sussex RH10 3RG·07702 896 910·[email protected]
How to check you’re dealing with usServing Crawley, East Grinstead, Brighton and businesses across Sussex · UK-wide remote support
Copyright 2026. Systems Secure. All Rights Reserved.