Call Anytime

0800 208 8456

Email Security Checker

FREE SECURITY TOOL

Email Security Checker

Email spoofing is one of the most common methods attackers use to impersonate your business. A DMARC record tells email providers how to handle messages that fail authentication checks, protecting your customers, your staff, and your reputation. This tool generates the record for you, correctly formatted and ready to add to your DNS.

FREE SECURITY TOOL

Email Security Checker

Email spoofing is one of the most common methods attackers use to impersonate your business. A DMARC record tells email providers how to handle messages that fail authentication checks, protecting your customers, your staff, and your reputation. This tool generates the record for you, correctly formatted and ready to add to your DNS.

Why Check Your Email Security?

Email spoofing is one of the most common attack methods used against UK businesses. An attacker sends an email that appears to come from your domain, targeting your customers, suppliers, or staff. The email looks legitimate because there is nothing in your DNS to prove otherwise.

Three protocols protect against this:

SPF

Tells email providers which servers are authorised to send email from your domain.

DKIM

Adds a digital signature to every outgoing email, proving the message was not altered in transit.

DMARC

Ties SPF and DKIM together and tells email providers what to do when a message fails authentication.

How This Tool Works

Steps

1

Enter your domain

Type your domain name without "www" or "https." For example, yourbusiness.co.uk.

2

Click Check

The tool queries Google's public DNS servers to look up your SPF, DKIM, DMARC, and MX records. Everything runs in your browser. Nothing is sent to our servers.

3

optional

Review your grade

Your domain receives an instant A to F grade based on which protocols are configured and how strong they are.

4

Read the recommendations

Each section includes a status (Pass, Warning, or Fail), the actual DNS record found (if any), parsed details, and a plain-English recommendation for what to do next.

Understanding Your Results

Overall Grade

Your domain is scored out of 100 and given a letter grade:

A

90-100

Excellent email security

All key protocols are correctly configured.

B

70-89

Good email security

Most protocols are in place but could be strengthened.

C

50-69

Fair email security

Some gaps that need attention.

D

30-49

Poor email security

Significant gaps that leave your domain exposed.

F

0-29

Critical

Your domain has little or no email authentication in place.

SPF Record

Sender Policy Framework

SPF is checked by looking for a TXT record on your domain starting with v=spf1. The tool reports:

Status

Whether an SPF record was found.

Failure Policy

How strictly unauthorised senders are handled: Hard Fail is strongest, Soft Fail is a good starting point, and Neutral offers no protection.

Include Lookups

How many of the 10 allowed DNS lookups you are using. Exceeding 10 causes the entire record to fail.

IP Entries

Number of direct IP addresses in the record (these do not count against the lookup limit).

If no SPF record is found, use our Generator to create one.

DKIM Record

DomainKeys Identified Mail

DKIM is checked by looking for TXT records under common selectors such as “google”, “selector1”, and “selector2”. The tool checks 17 commonly used selectors.

Status

Whether a DKIM record was found.

Selectors

Which selectors have valid DKIM records.

DKIM is typically configured by your email provider (Microsoft 365, Google Workspace, etc.) rather than manually. If no DKIM record is found, check your provider's documentation for instructions on enabling it.

Note: DKIM selectors can be custom, so a “not found” result does not necessarily mean DKIM is not configured. It means no common selectors were detected.

DMARC Record

Reporting & Conformance

DMARC is checked by looking for a TXT record on _dmarc.yourdomain.com.

Status

Whether a DMARC record was found.

Policy

What happens on failure: "none" (monitor only), "quarantine" (send to spam), or "reject" (block entirely).

Aggregate Reports

Whether you have configured a destination for reports, which show you who is sending email from your domain.

Percentage

What percentage of failing messages the policy applies to.

If no DMARC record is found, use our generator to create one.

MX Records

Mail Exchange

MX records tell the internet which servers handle incoming email for your domain. The tool identifies your email provider based on the primary mail server.

Status

Whether MX records were found.

Provider

Detected provider (Microsoft 365, Google Workspace, Zoho, etc.).

Servers

How many mail servers are configured.

Email Security Checker

Check Your Domain

Enter your domain without "www" or "https." Uses public DNS to check your records.

Checking email security records...

What To Do Next

Well done. Your email authentication is strong. Review your records periodically, especially when you add or remove email services.
You have the basics in place but there are gaps. The most common issues are a DMARC policy set to “none” (monitor only) or missing DKIM records. Use the recommendations in each section to strengthen your configuration.
Your domain is at serious risk of email spoofing. Attackers could send phishing emails that appear to come from your business.
Well done. Your email authentication is strong. Review your records periodically, especially when you add or remove email services.
You have the basics in place but there are gaps. The most common issues are a DMARC policy set to “none” (monitor only) or missing DKIM records. Use the recommendations in each section to strengthen your configuration.
Your domain is at serious risk of email spoofing. Attackers could send phishing emails that appear to come from your business.
Use our free SPF Generator and DMARC Generator to create the records you need, or contact us for help.

Need Help Securing Your Email?

Configuring SPF, DKIM, and DMARC correctly requires understanding your email infrastructure. If you are not sure which services send email on behalf of your domain, or how to add DNS records, we can audit your email security and configure everything for you.
Call us: 0800 208 8456  |  Email: hello@cyberkaizen.co.uk