Is your domain spoofable?
Most small business domains fail at least one of SPF, DKIM, or DMARC. The usual outcome is your invoices landing in a customer's junk folder, or someone sending mail as you and getting away with it. Enter your domain, confirm your email, and we will read your public DNS and send you a written report on what is wrong and the exact records to publish.
Run the check
Two minutes of your time. The report lands in your inbox a few minutes after you click the confirmation link.
SPF
Do you have exactly one SPF record, does it stay under the 10-lookup limit, and does it end in -all or the toothless +all? Multiple SPF records is the single most common break we find.
DKIM
We probe the selectors your mail provider actually uses (Microsoft 365, Google Workspace, SendGrid, Mailchimp and friends), then check key length. 1024-bit keys still show up constantly.
DMARC
Published at all? Still sitting at p=none two years later? Is anyone reading the aggregate reports? Alignment set so it does not break your own mail when you tighten it?
The rest of it
MX sanity, MTA-STS, TLS-RPT, DNSSEC, BIMI readiness, and whether a parked or unused domain of yours is wide open for spoofing.
Before you type your domain in
- Why do you need my email?
- Because the report is emailed to you. We confirm the address first with a one-click link so nobody can use this tool to send mail to a stranger. That is also how we hold the limit of two reports per person.
- Is any of this private data?
- No. Every record we read is public DNS. Anyone can look it up. The value is that we read all of it at once, check it against current best practice, and write down what to do about it.
- What if I want it re-run later?
- Fix the records, then reply to the report email and ask. Two automated runs per person is the cap. Beyond that, a human at Sage looks at it with you.
- Will you sell my address or add me to a drip campaign?
- No. You get the report and one follow-up email asking if you want help fixing what it found. Reply "no thanks" and that ends it.
Already know it is broken and want it fixed properly? Get a written quote, or read up on our cybersecurity work first.