Deliverabilityfree check
Free check · no sign-up

Who can send email in your name?

Enter your domain name. We read its public records, then tell you whether a stranger can pass as you, and whether your own messages arrive.

Right now, somewhere

The “From:” field of an email is filled in freely, like the sender on the back of an envelope. Here's your customer's inbox, before and after your domain says who's allowed to write in its name.

Your customer receives your reminder: invoice #2041.

A stranger sends the same invoice, signed with your address, with his bank details.

In the list, nothing tells them apart: same name, same address.

Paid. Into the stranger's account.

You declare your policy: three lines at your domain registrar.

The same stranger tries again. The inbox checks the signature: it isn't there.

Spam. Your customer never opens it, and you know who tried.

Your real reminder now carries the “verified” mark.

What sorts this inbox takes three lines at your domain registrar.

Today, nothing in your customer's inbox shows this message is fake. Your domain may be in this position.

What decides where your messages land

All these inboxes apply the same three records to decide whether a message really comes from you. What protects you at one protects you at all of them.

Questions we get asked
Can someone really send email in my name?

Yes, and it's trivial. The “From:” field of an email is filled in freely, like the sender on the back of an envelope. Only three records in your domain let the recipient's server refuse a fake. If they're missing, or set up but not enforced, the fake gets through.

I have nothing to hide. Why should I care?

You're not the target: your customers are. The most common case is the fake invoice: a message that seems to come from your accounting, announcing new bank details. The customer pays, and it's your name that did the work.

What does this check measure?

Twelve checks in your domain's public DNS, grouped into five categories and scored out of 100. Who's allowed to send in your name, what a server should do with a fake, whether your messages are signed, whether your incoming mail is redundant, whether transport is encrypted. No message is sent, nothing is left on your site.

My signature isn't detected. Is that bad?

Not necessarily. The signature lives under a name only the sender knows; we query the most common ones. When none responds, we write “not detected” and this check leaves the calculation, instead of docking points for something we couldn't measure.

Do I need a contractor to fix this?

Rarely. These are lines to add wherever your domain name is managed, often three. The only delicate part is switching the policy to enforcing without blocking a legitimate sending service: that's done in stages, by reading the reports.

Check of example.com

0,0 s
0/ 100
Test in progress

Your score is building.

Each category adds the points it earns, and shows the ones you're missing.

0points out of 100
Preparing the check Connecting to the site
Connection Connecting to the site
Check details