Can someone send invoices in your name?
For a great many companies the answer is yes — and nobody has ever told them. This check reads the same public records an attacker reads, and translates them into plain language.
The check queries publicly readable DNS records and the website's TLS certificate only. No port scan, no access to your systems, no sign-up. We do not store the domain you check.
Whether strangers can send email in a domain's name comes down to three DNS records: SPF states which servers are allowed to send, DKIM signs outgoing messages, and DMARC tells the receiving server what to do with messages that fail. If DMARC is missing or set to `p=none`, nothing is blocked — the message lands in the recipient's inbox as if it came from the company.
Common questions about this check
- Is this check legal if I enter someone else's domain?
- Yes. It queries only DNS records and the publicly served TLS certificate — the same data every mail server and every browser reads during normal operation. No port scan takes place and nothing is altered on any external system. That is precisely why the check is deliberately limited to these tests.
- Why does DMARC matter more than SPF?
- SPF and DKIM establish whether a message is genuine. DMARC is the only one of the three that tells the recipient what to do with a message that is not. Without DMARC a message can fail both checks and still be delivered — the recipient simply has no instruction.
- What does p=none mean?
- It is the observation setting: DMARC is evaluated and optionally reported on, but nothing is blocked. It is meant as a transition lasting a few weeks, so you can see who is sending in your name. In practice it often stays for years and gives a false sense of security.
- No DKIM was found — does that mean I have none?
- Not necessarily. The selector a DKIM key sits under is freely chosen and cannot be enumerated from outside. The check tries the common names. Finding nothing is an indication, not proof — which is why this item is not counted as a fault.
- How long does it take to fix what was found?
- The DNS records themselves are a matter of minutes. The effort sits before that: working out which services actually send in your name — ERP, newsletter tool, accounting, point-of-sale. Anyone who enforces DMARC before that list is complete will block their own invoices. That is why it is done in stages.
Found something you did not expect?
The records in this report can usually be put right in a single morning. Send us the result and we will tell you which part is yours to do and which part is ours.