Enter your business domain. We read the public records that mail servers use to decide whether a message claiming to be from you is genuine, and tell you in plain English how exposed you are.
Reads public DNS records only. Nothing about you is collected or stored.
If you run Microsoft 365 or Google Workspace, all three records are settings your provider gives you and take under an hour to publish. If you would rather someone did it with you, that is part of our Essential Eight baseline. And if you want the full picture of what your website exposes, not just email, create a free account and run the scanner.
It is a normal-looking message from your domain to one of your clients, saying your bank details have changed. Whether it gets delivered depends on three records most firms have never looked at.
A list of the servers allowed to send email for your domain. Without it, any server anywhere can claim to be you.
A signature on each message proving it was not altered and really came from your mail system. Turned on in your provider, published as two records.
The instruction to the receiving server: if a message fails the checks above, junk it or reject it. Set to "none" it only watches. Set to "reject" it stops the fraud.
See whether a password has appeared in a public data breach. Also free, entirely in your browser.
Password breach check