Home / Check
Can your domain be used to write to your customers?
Type your domain and in a few seconds see whether anyone can send email that looks like yours. Free, without leaving your address.
| Time | a few seconds |
| Data required | the domain only |
| Email required | none |
| What we read | public DNS records |
| Already run on | 1,263 shops |
What we look at
The same four records we measured across 1,263 Italian online shops, where 84.2% turned out to be forgeable. SPF says which servers may send in your name. DKIM signs your emails. DMARC says what to do with mail that fails the checks. MTA-STS protects incoming mail. The score weighs what it finds: a missing DMARC counts for far more than a missing MTA-STS.
What we do not do
We send you no email, we store nothing you type, we ask for no sign-up. We read public DNS records, the same ones anyone can read with two commands: if you would rather do it by hand, the guide shows how.
One stated limit: we look for DKIM across a list of common selectors. If your provider uses an unusual one, it shows as “to verify” even when it exists. That is why we never mark it as failing.
I got a red result. Now what
These are DNS changes, not website changes: whoever manages the domain makes them in the registrar panel, and no developer is needed. The safe route takes three steps of about a month each, observe first and tighten later, so legitimate email is never blocked by mistake. It is set out step by step in the guide.
If you would rather we handled it, the full picture also lists who is already sending in your name, which is the part you actually need in order to break nothing. We send it free within 48 working hours, and only if you ask.
This check is not legal advice and does not replace reading your DMARC reports.