Laptop displaying email security protection with SPF, DKIM and DMARC verification checks.

How Can I Check If My Business Email Domain Can Be Spoofed?

September 11, 20264 min read

Quick Answer

You can check whether your business email domain is protected against spoofing by checking its SPF, DKIM and DMARC settings.

We have created a free Domain Spoofing Checker that lets you enter your business domain and quickly check the email authentication settings currently published for it.

You do not need to understand DNS or email security to run the check.

Run our free Domain Spoofing Checker

What is email domain spoofing?

Email domain spoofing is when a criminal sends an email that appears to have come from your business even though it did not.

For example, your genuine email address might be:

[email protected]

A criminal may try to send an email that also appears to come from:

[email protected]

They could then contact your customers, suppliers or staff pretending to be your business.

Typical examples include:

  • Asking a customer to pay an invoice into a different bank account

  • Sending a fake Microsoft 365 login page

  • Pretending to be a director asking for an urgent payment

  • Sending malicious attachments or links

  • Contacting your suppliers while pretending to be someone from your company

This is why protecting your email domain is important even if your own Microsoft 365 or Google Workspace accounts have never been hacked.

How does the Domain Spoofing Checker work?

Our Domain Spoofing Checker checks the email security information published for your domain.

It looks at the technologies used to help receiving email systems decide whether an email claiming to come from your domain is genuine.

The three main protections are:

What is SPF?

SPF — Sender Policy Framework — identifies which mail systems are authorised to send email for your domain.

For example, if your company uses Microsoft 365, your SPF record can tell other email providers that Microsoft is an authorised sender.

What is DKIM?

DKIM — DomainKeys Identified Mail — adds a digital signature to outgoing email.

Receiving mail systems can use this signature to help confirm that an email genuinely came through an authorised mail system and has not been altered in transit.

What is DMARC?

DMARC — Domain-based Message Authentication, Reporting and Conformance — brings SPF and DKIM together and tells receiving email providers what they should do when an email fails authentication.

A DMARC policy can generally be set to:

None – monitor the email but do not ask receiving systems to block it.

Quarantine – ask receiving systems to treat suspicious messages more cautiously, normally by putting them into spam or junk.

Reject – ask receiving systems to reject messages that fail DMARC authentication.

For organisations that have correctly configured their legitimate email services, DMARC at reject is normally the end goal.

Does having an SPF record mean my domain is protected?

Not necessarily.

This is a common misunderstanding.

A business may have had an SPF record configured when Microsoft 365 or another email service was originally installed, but that does not automatically mean the domain is properly protected against spoofing.

SPF, DKIM and DMARC work together.

We regularly find domains where one part has been configured but the complete email authentication setup has never been finished.

What does a DMARC policy of “none” mean?

A domain with DMARC configured as:

p=none

is generally in monitoring mode.

DMARC reports can still provide extremely useful information about who is sending email using the domain, but the policy is not asking receiving email systems to quarantine or reject messages that fail DMARC.

Moving directly from no DMARC protection to p=reject without checking legitimate email services first can cause genuine email to be rejected.

DMARC should therefore be configured and tested properly before full enforcement is enabled.

Could criminals still impersonate my business if DMARC is configured?

Yes.

DMARC is designed to make it much harder for criminals to directly spoof your actual domain, but it cannot prevent every type of impersonation.

For example, a criminal could register a similar-looking domain such as:

yourcornpany.co.uk

instead of:

yourcompany.co.uk

They could also use a completely unrelated email address but change the display name to the name of your managing director.

A compromised genuine mailbox is another different type of attack.

Email domain protection should therefore form part of your overall cyber security rather than being treated as the only protection required.

Should I check domains that don't send email?

Yes.

Domains owned by your business can potentially be abused even if you do not normally send email from them.

Businesses often own several domains, including:

  • Old company names

  • Alternative spellings

  • Marketing domains

  • Domains used only for websites

  • Domains belonging to other companies within the group

These should not simply be forgotten.

How can I check my business domain?

We have made this simple.

Use the Systems Secure Domain Spoofing Checker, enter your domain name and run the check.

The tool will help you see whether the important email authentication protections are present and highlight areas that may need further investigation.

Check your domain now with our free Domain Spoofing Checker.

If the results show that your domain is not properly protected, Systems Secure can also help investigate the configuration and safely implement SPF, DKIM and DMARC without disrupting legitimate business email.

James Batt
James Batt is the founder and lead cyber security consultant at Systems Secure, where he helps small businesses build rock-solid digital defences without the jargon. He holds CISSP, C|CISO and CEH certifications, with a deep background in endpoint protection, cloud hardening and security audits, and he's on a mission to make cyber security accessible, understandable and practical for real-world business owners. Based in Copthorne, West Sussex, James works on-site with businesses across Sussex and remotely with clients UK-wide. When he's not fending off threats or simplifying tech-speak, he's probably out walking his German Shorthaired Pointer, Fern — or getting distracted by Pretzel, the office dachshund.
Back to Blog
Image

Innovation

Fresh, creative solutions.

Excellence

Excellence

Top-notch services.

FOLLOW US

Systems Secure Ltd

6 The Meadow, Copthorne, West Sussex. RH10 3RG

[email protected]

07702 896 910

Company Registration: 7295869

Copyright 2026. Systems Secure. All Rights Reserved.