Free tool
Is Your Email Actually Getting Delivered?
Just because you hit send doesn't mean your message arrived. Your domain's DNS records tell the world's inboxes whether your email is legitimate - and if they're missing or weak, your messages land in spam, get blocked entirely, or worse: anyone can send email pretending to be you. Enter your work email and we'll scan your company domain's email security setup in seconds. Results appear on screen instantly and we'll email you a copy.
Scan your domain
The three records that decide whether your email lands
What is SPF?
SPF (Sender Policy Framework) is a DNS record that tells inboxes which mail servers are allowed to send email for your domain. When a receiving inbox sees a message from you, it checks SPF to confirm the sending server is on your approved list. Without SPF, anyone can send email as you and receiving inboxes have no easy way to tell.
What is DKIM?
DKIM (DomainKeys Identified Mail) digitally signs your outgoing messages using a private key, and publishes the matching public key in DNS. Receiving inboxes use the public key to verify the message really came from you and wasn't tampered with in transit. It's the tamper-evident seal on the envelope.
What is DMARC?
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells inboxes what to do when a message claiming to be from your domain fails SPF or DKIM: monitor, quarantine, or reject. Without DMARC, the default answer is usually "deliver it anyway" - which is exactly how spoofed email keeps working.
The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.
