Can scammers send email in your name?
Enter your company's domain. We'll check its SPF, DKIM and DMARC records and show you what to fix.
How to turn on protection without blocking your own email
List every sender
Your mail service, newsletter tool, invoicing software and website forms all send in your name and must be in the SPF record.
Turn on DKIM
Turn on DKIM signing with your domain in each sending service. The service gives you the record to add to DNS.
Publish DMARC with p=none
Add a reporting address and watch for a few weeks who sends email in your name.
Tighten to reject
Once all genuine senders pass, change the policy to quarantine and later to reject.
Frequently asked questions
Does the check change anything on my domain?
No. We only read public DNS records, the same ones every mail service sees. We do not keep the domains you enter.
Why wasn't DKIM found when we use it?
The DKIM record sits under a selector chosen by your mail service, and there is no public list of selectors. We check the most common ones. You can find yours in the header of an email you sent (DKIM-Signature, the s= field) and enter it in the check.
How long until changes show up?
Usually a few minutes, sometimes a few hours, depending on the record's TTL. If you have just changed a record, check again later.
Should I use “~all” or “-all”?
When your DMARC policy is “quarantine” or “reject”, DMARC makes the decision, so both work much the same. “~all” is safer while not every sending service is in your SPF record yet.
Read more
- Email spoofing: how scammers send email in your nameFour ways scammers use your name, how SPF, DKIM and DMARC work together and how to turn DMARC on in stages.
- CEO fraud and invoice fraudWhat happens when scammers pose as a manager or a supplier, and the one rule that stops most of these payments.
- Phishing glossarySPF, DKIM, DMARC, BEC, spoofing and other terms explained in plain language.
Sources
The standards and mail provider guidance this check is based on.
- IETFRFC 7208: Sender Policy Framework (SPF)
- IETFRFC 6376: DomainKeys Identified Mail (DKIM) signatures
- IETFRFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)
- NCSC (UK)Email security and anti-spoofing
- GoogleEmail sender guidelines
- Google WorkspaceSet up DMARC
- MicrosoftSet up DMARC to validate email in Microsoft 365
DMARC does not stop look-alike domains
It only protects your exact domain. Emails from a similar domain (such as company-eu.com), from gmail.com or from a supplier's hacked mailbox pass every check, so people have to spot them. Opsinel sends employees realistic phishing emails and shows anyone who clicks a short lesson straight away.