SPF — sender policy
SPF lists who’s allowed to send email as your domain. A hard fail (-all) is what actually stops spoofers.
Enter your domain to look up the three DNS records that decide whether criminals can send email as your business. You will see each record exactly as it is published, what is wrong with it, and what to change. Lookups run from your browser using public DNS, so nothing is sent to us.
Scored across these three records only. Our fullEmail Security Checker also weighs MX, MTA-STS and TLS-RPT.
SPF lists who’s allowed to send email as your domain. A hard fail (-all) is what actually stops spoofers.
DKIM cryptographically signs your mail so receivers can verify it wasn’t tampered with — and it’s required for DMARC to pass reliably.
DMARC is the record that tells inboxes to reject or quarantine forged email — the single biggest lever against domain spoofing and phishing.
Use — Guide
FAQ — Questions
They are three DNS records that together prove your email is really from you. SPF lists the servers allowed to send as your domain, DKIM signs each message so it cannot be altered in transit, and DMARC tells receiving mail servers what to do when a message fails those checks. Without all three, anyone can send email that appears to come from your business.
DKIM records are published under a selector, and the selector name differs between mail providers. We probe the selectors your mail provider normally uses plus a list of common ones, but we cannot know a custom selector. If yours is not found, enter your selector in the optional field and run the check again. Your mail platform shows the selector in its DKIM settings.
No. The lookups run in your browser against public DNS-over-HTTPS resolvers, so the domain you type never reaches us. Nothing is sent to Peritus Digital unless you choose to contact us.
p=reject is the goal, because it tells inboxes to throw away forged mail outright. Most businesses start at p=none to collect reports, then move to p=quarantine and finally p=reject once the reports show all legitimate mail is passing. Staying at p=none gives you visibility but no protection.
DNS changes usually apply within minutes, but can take up to a few hours depending on the TTL on your existing records. Re-run this check after you publish a change to confirm it is live.
More — Keep exploring
Want hands-on help, not just a check? Explore ourCyber Security service.
Need help closing these gaps?
Misconfigured or missing email-authentication records are one of the most common ways criminals impersonate a business to defraud its customers and staff. Our Newcastle team reviews your records, publishes the fixes, and moves your DMARC policy safely towards p=reject without breaking legitimate mail.
Prefer to build the records yourself? Use ourSPF & DMARC Record Generator.
Email yourself a combined report of the results you have collected. Anything flagged in red or amber is worth acting on — we can help you fix it.