Can scammers send email in your name?

Enter your company's domain. We'll check its SPF, DKIM and DMARC records and show you what to fix.

Know your DKIM selector?

We only read public DNS records and do not keep the domains you enter.

How to turn on protection without blocking your own email

  1. List every sender

    Your mail service, newsletter tool, invoicing software and website forms all send in your name and must be in the SPF record.

  2. Turn on DKIM

    Turn on DKIM signing with your domain in each sending service. The service gives you the record to add to DNS.

  3. Publish DMARC with p=none

    Add a reporting address and watch for a few weeks who sends email in your name.

  4. Tighten to reject

    Once all genuine senders pass, change the policy to quarantine and later to reject.

Frequently asked questions

Does the check change anything on my domain?

No. We only read public DNS records, the same ones every mail service sees. We do not keep the domains you enter.

Why wasn't DKIM found when we use it?

The DKIM record sits under a selector chosen by your mail service, and there is no public list of selectors. We check the most common ones. You can find yours in the header of an email you sent (DKIM-Signature, the s= field) and enter it in the check.

How long until changes show up?

Usually a few minutes, sometimes a few hours, depending on the record's TTL. If you have just changed a record, check again later.

Should I use “~all” or “-all”?

When your DMARC policy is “quarantine” or “reject”, DMARC makes the decision, so both work much the same. “~all” is safer while not every sending service is in your SPF record yet.

DMARC does not stop look-alike domains

It only protects your exact domain. Emails from a similar domain (such as company-eu.com), from gmail.com or from a supplier's hacked mailbox pass every check, so people have to spot them. Opsinel sends employees realistic phishing emails and shows anyone who clicks a short lesson straight away.