These three DNS records decide whether someone can send email that looks like it came from your company. Enter your domain to see what you publish today, and what to change.
We read public DNS records. Nothing is sent, nothing is stored.
SPF lists the servers allowed to send email for your domain. DKIM signs your messages so the receiver can tell they were not altered. DMARC tells the receiver what to do when a message fails those checks, and it is the one that actually blocks anything.
Without DMARC, a receiving server has no instruction from you, so a forged message is usually delivered. Anyone can put your company name in the From field and write to your clients, your accountant or your staff. Those emails ask for an invoice to be paid to a new account, and they work often enough to be a business of their own.
Start at p=none, which asks receivers to report without blocking anything. Read the reports for a few weeks to find your own senders, the invoicing tool and the newsletter included. Once your real mail passes, move to p=quarantine, then p=reject. Going straight to reject can send your own invoices to spam.
Email is one way in. Leaked staff passwords, files published by mistake and domains registered to look like yours are the others, and none of them show up in DNS.
The full scan adds leaked employee passwords, exposed documents and lookalike domains, explained in plain language. No login, and it takes about a minute.