Email Security Analyser

Grade any domain's email authentication posture - SPF, DMARC, DKIM, MTA-STS, TLS-RPT and BIMI - in one check.

About this tool

SPF and DMARC together prevent spoofing, without them, anyone can send email claiming to be your domain, enabling phishing campaigns that your customers and partners cannot distinguish from legitimate mail. A DMARC policy of p=reject is the gold standard; p=none provides visibility but no enforcement. MTA-STS ensures that mail servers delivering to your domain negotiate TLS, protecting the channel in transit. DKIM cryptographically signs outbound messages; its absence means recipient servers cannot verify authenticity. Missing these controls is a common SOC 2 and ISO 27001 finding. Pair this check with the DNS Lookup tool to inspect the raw records directly.

Related tools